CVE · Medium

CVE-2024-5639 — User Profile Picture [metronet-profile-picture] < 2.6.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-5639 User Profile Picture [metronet-profile-picture] < 2.6.2 Authorization Bypass Through User-Controlled Key Medium 4.3 < 2.6.2 2.6.2 2024-06-20

CVE-2024-5639

The User Profile Picture plugin for WordPress contains an Insecure Direct Object Reference vulnerability affecting versions 2.6.1 and earlier in the 'rest_api_change_profile_image' function. The flaw stems from insufficient validation of user-supplied input parameters, allowing authenticated users with Author privileges or higher to modify profile pictures belonging to any other user on the site. This vulnerability impacts all versions up to and including 2.6.1, with a fix available in version 2.6.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.