CVE-2021-24473: User Profile Picture < 2.6.0 - Arbitrary User Picture Change/Deletion via IDOR
Published Aug 2, 2021
·Updated
The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the uploadimage capability (by default author and above) to change and delete the profile pictures of other users (including those with higher roles).
Affected Software
1 affected component
Cozmoslabs User Profile Picture Wordpress<2.6.0
Event History
Aug 2, 2021
CVE Published
via MITRE·10:32 AM
Data Sourced
via MITRE·10:32 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-24473.
2
What is the severity of CVE-2021-24473?
The severity of CVE-2021-24473 is medium with a CVSS score of 5.4.
3
What is the affected software in CVE-2021-24473?
The affected software in CVE-2021-24473 is the User Profile Picture WordPress plugin before version 2.6.0.
4
What is the impact of CVE-2021-24473?
CVE-2021-24473 allows users with the upload_image capability to change and delete the profile pictures of other users, including those with higher roles.
5
How can I fix CVE-2021-24473?
To fix CVE-2021-24473, update the User Profile Picture WordPress plugin to version 2.6.0 or higher.