CVE · Low

CVE-2026-61971 — User Profile Picture [metronet-profile-picture] < 2.6.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-61971 User Profile Picture [metronet-profile-picture] < 2.6.4 Low 2.7 < 2.6.4 2.6.4 2026-07-13

CVE-2026-61971

The User Profile Picture plugin for WordPress contains a flaw that allows authorized users with elevated permissions to bypass intended security checks by manipulating a specific input parameter without proper verification. This vulnerability affects versions 2.6.3 and earlier of the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.