Authorization Bypass Vulnerability in Simple User Avatar by Matteo Manna
CVE-2026-57676
4.3MEDIUM
What is CVE-2026-57676?
An authorization bypass vulnerability has been identified in the Simple User Avatar plugin developed by Matteo Manna. This issue allows attackers to exploit incorrectly configured access control security levels, leading to unauthorized access to sensitive user data. The vulnerability affects versions of the Simple User Avatar plugin from n/a through 4.9, potentially compromising the security of user accounts if not addressed.
Affected Version(s)
Simple User Avatar <= 4.9