User Profile Picture
User Profile Picture has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Authorization Bypass Through User-Controlled Key, behind 2 of the records (100%).
Every one of the 2 issues recorded for User Profile Picture has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. User Profile Picture is installed on roughly 40,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-61971User Profile Picture <= 2.6.3 - Authenticated (Author+) Insecure Direct Object Reference
Read the full analysisVulnerability Records

User Profile Picture
Author
Cozmoslabs
User Profile Picture is no longer under active development, but will continue to work as is. We have integrated the current functionality in Profile Builder where it will actively be maintained, and we recommend migrating to it. Set or remove a custom profile image for a user using the standard WordPress media upload tool. View Documentation and Examples Users must have the ability to upload images (typically author role or greater). You can use the plugin Profile Builder to allow other roles (e.g. subscribers) the ability to upload images. A template tag is supplied for outputting to a theme and the option to override a user’s default avatar is also available. Documentation and Feedback See the documentation on GitHub. Please Rate the Plugin.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C