Junglewise Threat Intelligence

CVE-2026-61971: Cozmoslabs User Profile Picture IDOR in metronet-profile-picture

CVE-2026-61971 · Severity: low · CVSS 2.7 · Published 2026-07-13

Vendors: Cozmoslabs.

Executive brief

The User Profile Picture plugin for WordPress, which allows users to upload and manage custom profile images, contains a security flaw in its access control settings. An authorized user with high-level permissions could potentially bypass intended restrictions to modify data they should not have access to. While the risk to data confidentiality is low, it could allow for unauthorized changes to user profile information.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the Cozmoslabs User Profile Picture plugin (metronet-profile-picture) for WordPress. The flaw stems from an authorization bypass through a user-controlled key, allowing attackers to exploit incorrectly configured access control security levels. An attacker with high-level administrative or editor privileges can leverage this to perform unauthorized modifications. The vulnerability is addressed in version 2.6.4.

Affected products

  • Cozmoslabs User Profile Picture (metronet-profile-picture) <= 2.6.3

Timeline

  • 2026-07-13: advisory: Published by Patchstack and NVD
  • 2026-07-13: disclosed

References