Input validation vulnerability in One User Avatar | User Profile Picture 2.3.7

The One User Avatar WordPress plugin before version 2.3.7 had a security issue that allowed people with Contributor level access to do something called “”Stored Cross-Site Scripting attacks””. This type of attack is when someone adds malicious code to the website that can be used to steal information. The plugin did not properly protect against this type of attack.

Detected in:

One User Avatar | User Profile Picture fixed vulnerable versions: >= * < 2.3.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.