### [CVE-2023-6384](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6384) ![](https://img.shields.io/static/v1?label=Product&message=WP%20User%20Profile%20Avatar&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=0%3C%201.0.1%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-639%20Authorization%20Bypass%20Through%20User-Controlled%20Key&color=brighgreen) ### Description The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar ### POC #### Reference - https://wpscan.com/vulnerability/fbdefab4-614b-493b-a9ae-c5aeff8323ef/ #### Github No PoCs found on GitHub currently.