Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2024-11-21
CVE-2021-24675 - One User Avatar Plugin
The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is embed. As a result, attackers could make logged in user change their avatar via a CSRF attack
PLUGIN
One User Avatar
CVE-2021-24675
Risk Score
Threat Entry
Updated 2024-11-21
CVE-2021-24672 - One User Avatar Plugin
The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
PLUGIN
One User Avatar
CVE-2021-24672
Risk Score
