{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/one-user-avatar--user-profile-picture--2.5.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-18983"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["One User Avatar | User Profile Picture (\u003c= 2.5.4)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) and Remote Code Execution (RCE) in versions up to and including 2.5.4. The vulnerability exists within the wpua_action_process_option_update function. The flaw is rooted in the implementation of wp_handle_upload(), which fails to enforce a strict MIME-type allow-list and instead relies on attacker-supplied Content-Type headers for validation. Because the plugin does not properly perform post-write validation or remove files that fail verification, authenticated users with subscriber-level access (if permitted by an administrator to upload avatars) can upload files with the .dxfp extension. These files can be leveraged to bypass security controls and achieve arbitrary code execution on the underlying web server.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers with subscriber-level permissions to execute arbitrary code on the web server, potentially leading to full site compromise, unauthorized data access, and lateral movement within the hosting environment. This vulnerability affects all WordPress installations utilizing the One User Avatar plugin version 2.5.4 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the One User Avatar | User Profile Picture plugin to the latest version immediately to remediate the file validation flaw.\u003c/li\u003e\n\u003cli\u003eReview WordPress plugin configuration settings to ensure subscribers are not granted unnecessary permissions to upload files or avatars.\u003c/li\u003e\n\u003cli\u003eAudit the web server upload directory for files with unusual extensions, specifically .dxfp, which may indicate exploitation attempts.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP POST requests to avatar processing endpoints originating from accounts with subscriber-level privileges.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T07:11:54Z","date_published":"2026-08-28T07:11:54Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-18983/","summary":"The One User Avatar | User Profile Picture WordPress plugin versions 2.5.4 and earlier contain a stored XSS and RCE vulnerability via improper file type validation in the avatar upload process.","title":"Stored XSS and RCE vulnerability in One User Avatar WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-18983/"}],"language":"en","title":"CraftedSignal Threat Feed - One User Avatar | User Profile Picture (\u003c= 2.5.4)","version":"https://jsonfeed.org/version/1.1"}