Executive brief
The Simple User Avatar plugin for WordPress, which allows users to upload and manage custom profile pictures, contains a security flaw in its access control. An authenticated user could potentially bypass intended security restrictions to view or interact with data belonging to other users. This could lead to unauthorized access to sensitive user information or profile settings.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Matteo Manna Simple User Avatar plugin for WordPress (versions up to and including 4.9). The flaw stems from the application using user-controlled keys to access objects without sufficient authorization checks. A remote attacker with subscriber-level privileges can exploit this by manipulating input parameters to access or modify data associated with other users. This vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). A fix is available in version 5.0.
Affected products
- Matteo Manna Simple User Avatar n/a through 4.9
Timeline
- 2026-06-15: other: Reported by researcher Ananda Dhakal
- 2026-06-29: advisory: Published by Patchstack and NVD
- 2026-06-29: patched: Version 5.0 released to address the vulnerability