Access Control Misconfiguration in Author Avatars List Plugin by Paul Bearne
CVE-2026-39690
5.3MEDIUM
What is CVE-2026-39690?
A missing authorization vulnerability exists in the Author Avatars List/Block plugin by Paul Bearne, impacting versions up to 2.1.25. This issue occurs due to incorrectly configured access control security levels, which may allow unauthorized users to exploit certain features, leading to potential exposure of sensitive user data. Website administrators should ensure their installations are updated to avoid security risks associated with this misconfiguration.
Affected Version(s)
Author Avatars List/Block 0 <= 2.1.25