VYPR

User Profile Picture

by Cozmoslabs

CVEs (1)

  • CVE-2024-5639MedJun 21, 2024
    risk 0.21cvss 4.3epss 0.00

    The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it possible for…