CVE-2025-13320 | wpusermanager WP User Manager Plugin up to 2.9.12 on WordPress filter_input current_user_avatar file inclusion
A vulnerability has been found in wpusermanager WP User Manager Plugin up to 2.9.12 on WordPress and classified as problematic. This issue affects the function filter_input. Performing manipulation of the argument current_user_avatar results in file inclusion.
This vulnerability is reported as CVE-2025-13320. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.