CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a...Show more |
1Cozmoslabs 1User Profile Picture Nov 21, 2024 Aug 2, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users...Show more |
1Cozmoslabs 1User Profile Picture Nov 21, 2024 Apr 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included passwor...Show more |