📦 User Profile Picture

by Cozmoslabs

🔍 What is User Profile Picture?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-24170

HIGH CVSS 7.5 Apr 5, 2021

The User Profile Picture WordPress plugin before version 2.5.0 exposed sensitive user data through its REST API endpoint. Users with upload_files capability could access password hashes, activation ke...

CVE-2024-5639

MEDIUM CVSS 4.3 Jun 21, 2024

The User Profile Picture WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Author-level permissions or higher to change any user's profile...