Cozmoslabs
Cozmoslabs User Profile Picture: vulnerabilidades y CVE
Cozmoslabs User Profile Picture tiene 4 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-61971 | Baja (2.7) | 0.31% | — | 13 jul 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User… |
| CVE-2024-5639 | Media (4.3) | 0.41% | — | 21 jun 2024 | The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a… |
| CVE-2021-24473 | Media (5.4) | 0.78% | — | 2 ago 2021 | The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other… |
| CVE-2021-24170 | Alta (7.5) | 4.8% | — | 5 abr 2021 | The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included… |
Otros productos de Cozmoslabs
Profile Builder · 28Translatepress · 14Membership & Content Restriction - Paid Member Subscriptions · 7Paid Member Subscriptions · 6Paid Membership Subscriptions · 6WP Webhooks · 2User Profile Builder · 2Client Portal · 2Custom Post Types AND Custom Fields Creator · 1Translatepress-multilingual · 1Passwordless Login · 1Profile Builder PRO · 1