User Profile Picture <= 2.6.3 - Authenticated (Author+) Insecure Direct Object Reference
medium
The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.6.3 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.4
- Disclosed:
- Jul 31, 2026
CVE-2026-61971 on NVD →
User Profile Picture [metronet-profile-picture] < 2.6.2
unknown
[en] The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level acce...
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.2
- Disclosed:
- Jun 21, 2024
CVE-2024-5639 on NVD →
User Profile Picture <= 2.6.1 - Authenticated (Author+) Insecure Direct Object Reference to Profile Picture Update
medium
The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access an...
- CVSS:
- 4.3
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.2
- Disclosed:
- Jun 20, 2024
CVE-2024-5639 on NVD →
User Profile Picture [metronet-profile-picture] < 2.6.0
unknown
[en] The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users (including those with higher roles).
- Affected:
- up to 2.6.0
- Fixed in:
- 2.6.0
- Disclosed:
- Aug 2, 2021
CVE-2021-24473 on NVD →
User Profile Picture [metronet-profile-picture] < 2.5.0
unknown
[en] The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.0
- Disclosed:
- Apr 5, 2021
CVE-2021-24170 on NVD →
User Profile Picture [metronet-profile-picture] < 2.5.0
unknown
Sensitive Information Disclosure vulnerability found by WordFence in WordPress User Profile Picture plugin (versions <= 2.4.0).
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.0
- Disclosed:
- Mar 3, 2021
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database