PT-2026-50637 · WordPress · Userswp
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
UsersWP versions prior to 1.2.64
Description
The UsersWP plugin for WordPress contains an Insecure Direct Object Reference (IDOR), which occurs when an application provides direct access to objects based on user-supplied input. The issue exists due to missing validation on a user-controlled key within the
user id parameter. This allows authenticated attackers with editor-level access or higher to reset and permanently delete the avatar or banner image of any user, including administrators, by clearing the avatar thumb or banner thumb metadata in the uwp usermeta table.Recommendations
Update the plugin to a version later than 1.2.63.
As a temporary workaround, restrict access to the
user id parameter for users with editor-level permissions until the update is applied.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Userswp