MEDIUM
Paul Bearne
CVE published 2026-04-08
CVE-2026-39690
A Missing Authorization vulnerability was found in the Author Avatars List/Block plugin. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels. The affected versions range from n/a through 2.1.25. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. It was published on 2026-04-08T09:16:41.110Z and last modified on 2026-07-24T20:10:00.147Z.