CVE-2024-10528: Ultimate Member <= 2.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Profile Picture Update
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wpajaxumresizeimage() and ajaxresizeimage() functions in all versions up to, and including, 2.8.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the profile pictures of other users.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10528?
CVE-2024-10528 has a medium severity due to the potential for unauthorized profile picture updates.
How do I fix CVE-2024-10528?
To fix CVE-2024-10528, update the Ultimate Member plugin to version 2.8.10 or later, which includes the necessary capability checks.
What systems are affected by CVE-2024-10528?
CVE-2024-10528 affects versions of the Ultimate Member plugin for WordPress up to and including version 2.8.9.
What type of vulnerability is CVE-2024-10528?
CVE-2024-10528 is a vulnerability related to unauthorized access allowing profile picture updates without proper permissions.
How can I determine if my site is vulnerable to CVE-2024-10528?
To determine if your site is vulnerable to CVE-2024-10528, check the version of the Ultimate Member plugin installed on your WordPress site.