Vulnerability Details CVE-2021-24473
The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users (including those with higher roles).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.8%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 5.5
Products affected by CVE-2021-24473
-
cpe:2.3:a:cozmoslabs:user_profile_picture:-
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.0
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.1
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.10
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.15
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.16
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.18
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.19
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.2
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.20
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.21
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.22
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.23
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.3
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.0.9
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.1.0
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.2.0
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.2.1
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.2.2
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.2.3
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.2.5
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.2.7
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.3.0
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.3.1
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.4.0
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.4.1
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.4.3
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.5.0
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.5.1
-
cpe:2.3:a:cozmoslabs:user_profile_picture:1.5.5
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.0.0
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.0.1
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.0.2
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.1.0
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.1.1
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.1.2
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.1.3
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.2.0
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.2.5
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.2.6
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.2.7
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.2.8
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.3.0
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.3.10
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.3.11
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.3.2
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.3.5
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.3.6
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.3.7
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.3.8
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.3.9
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.4.0
-
cpe:2.3:a:cozmoslabs:user_profile_picture:2.5.0