CVE-2025-49980

Publication date

2025-06-20 15:04:13

Family

Patchstack

State

PUBLISHED

Description

Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar wp-user-profile-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Profile Avatar: from n/a through <= 1.0.6.