What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Simple User Avatar: from n/a through 4.9.
Explanation of Vulnerability in Simple Terms
02Summary
Simple User Avatar versions up to 4.9 contain an authorization flaw that allows authenticated users to read sensitive information they should not access. The vulnerability requires a valid user account but no special privileges. An attacker with low-level access can view confidential data through the plugin's avatar functionality.
What an attacker can do
03Attacker Capabilities
Read sensitive information accessible through the avatar system that should be restricted.
Potential impact on your site
04Site Impact
Authenticated users can access confidential data beyond their permission level through the avatar feature.
Conditions required to exploit
05Prerequisites
Attacker must have a valid user account with low-level privileges on the site.
Key dates
06Disclosure timeline
June 29, 2026
CVE published
July 8, 2026
Record updated