CVE-2024-5639
The User Profile Picture plugin for WordPress contains an Insecure Direct Object Reference vulnerability affecting versions 2.6.1 and earlier in the 'rest_api_change_profile_image' function. The flaw stems from insufficient validation of user-supplied input parameters, allowing authenticated users with Author privileges or higher to modify profile pictures belonging to any other user on the site. This vulnerability impacts all versions up to and including 2.6.1, with a fix available in version 2.6.2.
Based on public CVE data (MITRE/NVD).