ZeroHour

CVE-2021-24473

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p54
Published
()
Modified
Description

The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users (including those with higher roles).

Vendors
cozmoslabs
Products
user profile picture
Ecosystems
WordPress
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.