plugin

User Photo Vulnerabilities

2 known security issues reported for the User Photo WordPress plugin. Most recent disclosed May 9, 2012.

1 high 1 medium

Running User Photo on your site? Check whether your installed version is affected.

Scan your site free

User Photo <= 0.9.5 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the userphoto_options_page function in user-photo.php in the User Photo plugin before 0.9.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to wp-admin/options-general.php. NOTE: some of these details are obtained from third pa...

CVSS:
6.1
Affected:
up to 0.9.5
Fixed in:
0.9.5.2
Disclosed:
May 9, 2012

CVE-2012-2920 on NVD →

User Photo <= 0.9.4 - Arbitrary File Upload

high

In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.

CVSS:
8.8
Affected:
up to 0.9.4
Fixed in:
0.9.5
Disclosed:
Feb 18, 2011

CVE-2013-1916 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database