Junglewise Threat Intelligence

CVE-2026-39690: Paul Bearne Author Avatars List/Block missing authorization

CVE-2026-39690 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

The Author Avatars List/Block plugin for WordPress, which is used to display user profile pictures on websites, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to bypass intended security restrictions and potentially access information that should be restricted. While the impact is considered moderate, it could lead to the exposure of user-related data.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Paul Bearne Author Avatars List/Block plugin for WordPress through version 2.1.25. The flaw stems from incorrectly configured access control security levels within the 'author-avatars' component. An unauthenticated remote attacker can exploit this lack of authorization checks to perform actions or access data that should be restricted to higher-privileged users. The vulnerability is exploitable over the network without user interaction. At the time of the advisory, no official patch has been confirmed, though users are advised to monitor for updates beyond version 2.1.25.

Affected products

  • Paul Bearne Author Avatars List/Block <= 2.1.25

Timeline

  • 2026-01-24: other: Vulnerability reported by researcher Nabil Irawan
  • 2026-02-23: advisory: Initial advisory published by Patchstack
  • 2026-04-08: disclosed: CVE-2026-39690 published to the NVD

References