CVE-2024-6410: ProfileGrid <= 5.8.9 - Authenticated (Subscriber+) Insecure Direct Object Reference
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.8.9 via the 'pmuploadimage' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the profile picture of any user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6410?
CVE-2024-6410 is classified as a medium severity vulnerability due to its potential for exploit through insecure direct object references.
How do I fix CVE-2024-6410?
To fix CVE-2024-6410, update the ProfileGrid – User Profiles, Groups and Communities plugin to version 5.8.10 or later.
What versions are affected by CVE-2024-6410?
All versions of the ProfileGrid – User Profiles, Groups and Communities plugin up to and including 5.8.9 are affected by CVE-2024-6410.
What is the nature of the vulnerability in CVE-2024-6410?
CVE-2024-6410 involves an insecure direct object reference due to insufficient validation on a user-controlled key.
Who is the vendor for CVE-2024-6410?
The vendor for CVE-2024-6410 is ProfileGrid, which develops the affected WordPress plugin.