Cozmoslabs User Profile Picture
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Cozmoslabs User Profile Picture.
By the Year
In 2026 there have been 1 vulnerability in Cozmoslabs User Profile Picture with an average score of 2.7 out of ten. User Profile Picture did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 2.70 |
| 2025 | 0 | 0.00 |
| 2024 | 1 | 4.30 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 2 | 6.45 |
It may take a day or so for new User Profile Picture vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Cozmoslabs User Profile Picture Security Vulnerabilities
Cozmoslabs Metronet-PIC: Auth Bypass via User Key <=2.6.3
CVE-2026-61971
2.7 - Low
- July 13, 2026
Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Profile Picture: from n/a through <= 2.6.3.
Insecure Direct Object Reference / IDOR
WordPress UserProfilePic 2.6.1 IDOR via rest_api_change_profile_image
CVE-2024-5639
4.3 - Medium
- June 21, 2024
The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to update the profile picture of any user.
Insecure Direct Object Reference / IDOR
The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue
CVE-2021-24473
5.4 - Medium
- August 02, 2021
The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users (including those with higher roles).
Insecure Direct Object Reference / IDOR
The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability
CVE-2021-24170
7.5 - High
- April 05, 2021
The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.
Information Disclosure
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Cozmoslabs User Profile Picture or by Cozmoslabs? Click the Watch button to subscribe.