Sceawere
Vulnerability Detail
CVE-2026-96518UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ProfilePress Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.9
- Creation Date
- 3h ago
- Vendor
- properfraction
- Product
- ProfilePress
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.17.3.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.9",
"pubDate": "2026-10-09T10:16:45.143Z",
"pubdate": "2026-10-09T10:16:45.143Z",
"executiveSummary": "A Missing Authorization vulnerability has been identified in the ProfilePress plugin (specifically affecting the wp-user-avatar component) for WordPress.\nThis security flaw allows unauthorized users to perform actions that should be restricted to privileged accounts, due to incorrectly configured access control security levels.\nThe vulnerability affects ProfilePress versions from n/a through 4.17.3.\nThe primary risk implication is the potential for unauthorized data modification or administrative action execution, which may lead to full site compromise if leveraged to manipulate user roles or sensitive profile data.\nAttackers can exploit this without requiring specialized privileges, as the application fails to adequately validate the authorization context of incoming requests before processing them.\nExploitation is feasible over a network and does not necessitate pre-existing account credentials, significantly lowering the barrier for entry for malicious actors targeting affected WordPress installations.",
"technicalDetails": "The root cause of this vulnerability lies in an improper implementation of authorization checks within the wp-user-avatar component of the ProfilePress plugin. In many WordPress plugins, authorization checks—typically performed via current_user_can() or similar permission-based hooks—are intended to ensure that a user has the appropriate capability to interact with specific controller actions or REST API endpoints.\nIn this specific instance, the plugin fails to verify the authorization level of the requester before executing functionality associated with user avatar management or related user profile operations. Because the access control security levels are incorrectly configured, the plugin treats requests from unauthenticated or low-privileged users as if they originated from an authorized administrator or the legitimate owner of the profile.\nThe attack flow commences when an attacker identifies the vulnerable endpoint exposed by the wp-user-avatar component. The attacker then crafts a malicious request—typically an HTTP POST or GET request directed at the affected URI. Since the backend lacks the necessary security gates, the server processes the request's parameters without verifying if the user identity possesses the requisite WordPress capabilities (e.g., 'manage_options' or 'edit_users').\nUpon successful invocation of the vulnerable function, the application may permit the unauthorized alteration of avatar data, potential metadata manipulation, or other functions intended solely for authenticated users. The lack of granular authorization checks allows an attacker to bypass legitimate security logic, effectively escalating their influence over the targeted user's data.\nThe exploitation does not require the attacker to be authenticated, meaning the attack surface is exposed to the public internet. By sending specially crafted requests, an attacker can trigger sensitive code paths that should have remained inaccessible. The post-exploitation impact is highly dependent on the functionality exposed through the improperly protected component, but generally includes unauthorized content modification, potential user data leakage, or the injection of malicious payloads if the avatar upload path lacks sufficient file-type validation following the initial authorization bypass.\nAffected versions include all versions from n/a up to and including 4.17.3. The vulnerability highlights a systematic failure in applying the principle of least privilege, where the plugin's architectural design incorrectly assumes that the path to the component is protected by higher-level global middleware that is, in fact, absent."
}