Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-50823 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin <= 1.4.11 versions. |
Tue, 28 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 28 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in ctltwp User Avatar user-avatar.This issue affects User Avatar: from n/a through <= 1.4.11. | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin <= 1.4.11 versions. |
| Title | WordPress User Avatar plugin <= 1.4.11 - Cross Site Scripting (XSS) vulnerability | WordPress User Avatar Plugin <= 1.4.11 is vulnerable to Cross Site Scripting (XSS) |
Tue, 28 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin <= 1.4.11 versions. | A vulnerability in ctltwp User Avatar user-avatar.This issue affects User Avatar: from n/a through <= 1.4.11. |
| Title | WordPress User Avatar Plugin <= 1.4.11 is vulnerable to Cross Site Scripting (XSS) | WordPress User Avatar plugin <= 1.4.11 - Cross Site Scripting (XSS) vulnerability |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 29 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:08:47.293Z
Reserved: 2023-10-24T13:10:12.433Z
Link: CVE-2023-46621
Updated: 2024-08-02T20:53:20.646Z
Status : Modified
Published: 2023-11-08T16:15:10.470
Modified: 2026-04-28T19:21:44.027
Link: CVE-2023-46621
No data.
OpenCVE Enrichment
No data.
EUVD