← WordPress Vulnerabilities
WordPress security by component

One User Avatar

One User Avatar allows users to upload and manage custom profile avatars.

One User Avatar (one-user-avatar) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 28, 2026; the highest published CVSS base score is 7.5.

Plugin slug: one-user-avatar

CVE-2026-18983: One User Avatar accepts potentially executable Subscriber uploads

One User Avatar through 2.5.4 calls wp_handle_upload() without a MIME allow-list and relies on the client-supplied Content-Type after writing the file, without cleaning rejected files. When an administrator has enabled Subscriber avatar uploads, a Subscriber can upload a potentially executable DXFP file and make remote code execution possible; PHP and SVG files are rejected.

PublishedAug 28, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for one-user-avatar
Safe version
Aug 28, 2026 CVE-2026-18983
One User Avatar accepts potentially executable Subscriber uploads
One User Avatar through 2.5.4 calls wp_handle_upload() without a MIME allow-list and relies on the client-supplied Content-Type after writing the file, without cleaning rejected files. When an administrator has enabled Subscriber avatar uploads, a Subscriber can upload a potentially executable DXFP file and make remote code execution possible; PHP and SVG files are rejected.
See mitigation notes
CVE7.5
NVDPending
Oct 18, 2021 CVE-2021-24675
One User Avatar: Cross-site request forgery
One User Avatar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD6.5
Oct 18, 2021 CVE-2021-24672
One User Avatar: Cross-site scripting
One User Avatar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4