Sceawere

Vulnerability Detail

CVE-2026-96337UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ProfilePress Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
properfraction
Product
ProfilePress
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.17.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-09T10:16:44.863Z",
  "pubdate": "2026-10-09T10:16:44.863Z",
  "executiveSummary": "A Missing Authorization vulnerability has been identified in the ProfilePress (formerly wp-user-avatar) plugin, impacting versions from n/a through 4.17.3.\nThis flaw involves incorrectly configured access control security levels, which allows unauthorized users to perform actions restricted to higher-privileged accounts.\nThe vulnerability falls under the category of Broken Access Control, specifically concerning the lack of sufficient authorization checks for sensitive functions.\nImpact: Successful exploitation can lead to unauthorized data modification, account management bypasses, or other actions restricted by privilege levels, compromising the integrity and security of the WordPress installation.\nAttacker Capabilities: An attacker can leverage this vulnerability to execute administrative or restricted functions without requiring legitimate authentication or the necessary permissions.\nExploitation Requirements: The flaw is exploitable over the network and does not require elevated privileges if the underlying security checks are entirely absent, potentially allowing unauthenticated or low-privileged users to interact with protected endpoints.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper implementation of access control checks within the ProfilePress plugin's codebase. Specifically, the plugin fails to perform adequate authorization verification for sensitive API endpoints or administrative actions.\nIn the affected versions (n/a through 4.17.3), the logic responsible for validating the requester's identity or capabilities is either omitted or incorrectly implemented before processing requests. This results in the exposure of privileged functions that should be guarded by robust security protocols.\nThe attack flow proceeds as follows: An attacker identifies an endpoint or function call within the ProfilePress plugin that triggers sensitive operations, such as user profile modification or avatar management. Because the server-side code lacks a strict check to verify if the current user possesses the required administrative capabilities (e.g., using current_user_can() or appropriate capability checks), the server processes the request regardless of the user's role.\nBy manipulating parameters within an HTTP request, the attacker can force the application to perform actions on behalf of the site administrator or another user. The lack of proper nonce verification or authorization headers allows the request to be accepted as legitimate, bypassing the expected security boundary.\nThe vulnerable component involves the plugin’s request handling logic where user-submitted data is processed without sufficient validation of the user's authorization status. Because these endpoints are exposed, an attacker can craft specifically tailored payloads to invoke these functions remotely.\nPost-exploitation impact may include unauthorized modification of user data, potential account takeovers, or the alteration of global plugin settings, which could be chained with other vulnerabilities to achieve a full site compromise. The exposure is effectively network-wide, provided the target application is accessible via the web, and the vulnerability does not necessitate an existing active session or administrative access prior to the attack."
}
CVE-2026-96337: ProfilePress Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere