Description
Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Profile Picture: from n/a through <= 2.6.3.
Published: 2026-07-13
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WordPress User Profile Picture plugin up to version 2.6.3 contains an Authorization Bypass through User-Controlled Key vulnerability, also known as IDOR. The flaw is caused by incorrectly configured access control that allows a user who can supply an arbitrary user ID to view or modify another user’s profile picture. The vulnerability does not grant broader access to account data or site configuration; it specifically enables unauthorized manipulation of a target user’s profile picture. This weakness is categorized as CWE-639.

Affected Systems

The affected product is the Cozmoslabs User Profile Picture WordPress plugin, including the original plugin name "WordPress User Profile Picture", for all versions from the earliest release up to and including 2.6.3. Any site running these versions is vulnerable unless the plugin has been removed or updated.

Risk and Exploitability

With a CVSS score of 2.7 the risk is considered low. The EPSS score is below 1%, indicating few or no known exploit attempts at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker would need to be authenticated or possess a valid user credential to provide a crafted URL or payload that forces the plugin to load another user’s profile picture resource. Successful exploitation would allow reading or overwriting another user’s picture but would not expose other site data. The weakness is explicitly identified as CWE-639.

Generated by OpenCVE AI on August 1, 2026 at 10:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WordPress User Profile Picture plugin to a version newer than 2.6.3.
  • If an upgrade is not immediately available, uninstall or delete the plugin to pictures and review role permissions to reduce the attack surface.
  • Review and adjust user role permissions to limit authenticated users' ability to view or modify other users' profile pictures.

Generated by OpenCVE AI on August 1, 2026 at 10:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Cozmoslabs
Cozmoslabs user Profile Picture
Wordpress
Wordpress wordpress
Vendors & Products Cozmoslabs
Cozmoslabs user Profile Picture
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Profile Picture: from n/a through <= 2.6.3.
Title WordPress User Profile Picture plugin <= 2.6.3 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Cozmoslabs User Profile Picture
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:38:02.877Z

Reserved: 2026-07-13T06:13:50.885Z

Link: CVE-2026-61971

cve-icon Vulnrichment

Updated: 2026-07-13T13:54:23.439Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:15:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key