CVE · Medium

CVE-2021-24473 — User Profile Picture [metronet-profile-picture] < 2.6.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24473 User Profile Picture [metronet-profile-picture] < 2.6.0 Authorization Bypass Through User-Controlled Key Medium 5.4 < 2.6.0 2.6.0 2021-06-28

CVE-2021-24473

The User Profile Picture plugin prior to version 2.6.0 contained an insecure direct object reference vulnerability that permitted users possessing the upload_image capability to modify or remove profile images belonging to other users, even administrators. By default, authors and higher-level roles have this capability, enabling them to exploit the flaw to alter or delete pictures of any user account in the system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.