Executive brief
The User Profile Picture plugin for WordPress, which allows users to upload and manage custom profile images, contains a security flaw in its access control settings. An authorized user with high-level permissions could potentially bypass intended restrictions to modify data they should not have access to. While the risk to data confidentiality is low, it could allow for unauthorized changes to user profile information.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Cozmoslabs User Profile Picture plugin (metronet-profile-picture) for WordPress. The flaw stems from an authorization bypass through a user-controlled key, allowing attackers to exploit incorrectly configured access control security levels. An attacker with high-level administrative or editor privileges can leverage this to perform unauthorized modifications. The vulnerability is addressed in version 2.6.4.
Affected products
- Cozmoslabs User Profile Picture (metronet-profile-picture) <= 2.6.3
Timeline
- 2026-07-13: advisory: Published by Patchstack and NVD
- 2026-07-13: disclosed