CVE-2026-18983 | onedesigns One User Avatar Plugin up to 2.5.4 on WordPress File Upload wpua_action_process_option_update cross site scripting
A vulnerability identified as problematic has been detected in onedesigns One User Avatar Plugin up to 2.5.4 on WordPress. Impacted is the function wpua_action_process_option_update of the component File Upload. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-18983. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More