CVE-2024-5639: User Profile Picture <= 2.6.1 - Authenticated (Author+) Insecure Direct Object Reference to Profile Picture Update
The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'restapichangeprofileimage' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to update the profile picture of any user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress User Profile Pictureto a version that resolves this vulnerability.Fixed in 2.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5639?
CVE-2024-5639 is classified as a high-severity vulnerability due to its potential impact on user data integrity.
How do I fix CVE-2024-5639?
To fix CVE-2024-5639, update the User Profile Picture plugin to version 2.6.2 or later.
What type of vulnerability is CVE-2024-5639?
CVE-2024-5639 is an Insecure Direct Object Reference vulnerability.
Who is affected by CVE-2024-5639?
The vulnerability affects all versions of the User Profile Picture plugin for WordPress up to and including 2.6.1.
What can attackers do with CVE-2024-5639?
Attackers can exploit CVE-2024-5639 to access or modify user profile images without proper permissions.