Impact
WordPress User Profile Picture plugin up to version 2.6.3 contains an Authorization Bypass through User-Controlled Key vulnerability, also known as IDOR. The flaw is caused by incorrectly configured access control that allows a user who can supply an arbitrary user ID to view or modify another user’s profile picture. The vulnerability does not grant broader access to account data or site configuration; it specifically enables unauthorized manipulation of a target user’s profile picture. This weakness is categorized as CWE-639.
Affected Systems
The affected product is the Cozmoslabs User Profile Picture WordPress plugin, including the original plugin name "WordPress User Profile Picture", for all versions from the earliest release up to and including 2.6.3. Any site running these versions is vulnerable unless the plugin has been removed or updated.
Risk and Exploitability
With a CVSS score of 2.7 the risk is considered low. The EPSS score is below 1%, indicating few or no known exploit attempts at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker would need to be authenticated or possess a valid user credential to provide a crafted URL or payload that forces the plugin to load another user’s profile picture resource. Successful exploitation would allow reading or overwriting another user’s picture but would not expose other site data. The weakness is explicitly identified as CWE-639.
OpenCVE Enrichment