plugin

Metronet Profile Picture Vulnerabilities

6 known security issues reported for the Metronet Profile Picture WordPress plugin. Most recent disclosed Jul 31, 2026.

2 medium

Running Metronet Profile Picture on your site? Check whether your installed version is affected.

Scan your site free

User Profile Picture <= 2.6.3 - Authenticated (Author+) Insecure Direct Object Reference

medium

The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.6.3 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.6.3
Fixed in:
2.6.4
Disclosed:
Jul 31, 2026

CVE-2026-61971 on NVD →

User Profile Picture [metronet-profile-picture] < 2.6.2

unknown

[en] The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level acce...

Affected:
up to 2.6.2
Fixed in:
2.6.2
Disclosed:
Jun 21, 2024

CVE-2024-5639 on NVD →

User Profile Picture <= 2.6.1 - Authenticated (Author+) Insecure Direct Object Reference to Profile Picture Update

medium

The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access an...

CVSS:
4.3
Affected:
up to 2.6.1
Fixed in:
2.6.2
Disclosed:
Jun 20, 2024

CVE-2024-5639 on NVD →

User Profile Picture [metronet-profile-picture] < 2.6.0

unknown

[en] The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users (including those with higher roles).

Affected:
up to 2.6.0
Fixed in:
2.6.0
Disclosed:
Aug 2, 2021

CVE-2021-24473 on NVD →

User Profile Picture [metronet-profile-picture] < 2.5.0

unknown

[en] The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Apr 5, 2021

CVE-2021-24170 on NVD →

User Profile Picture [metronet-profile-picture] < 2.5.0

unknown

Sensitive Information Disclosure vulnerability found by WordFence in WordPress User Profile Picture plugin (versions <= 2.4.0).

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Mar 3, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database