S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Sep 15, 2025

CVE-2021-24170 Scanner

CVE-2021-24170 Scanner - Information Disclosure vulnerability in User Profile Picture

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24170
7.5
CVSS

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
User Profile Picture
AFFECTED< 2.5.0SAFE ✓≥ 2.5.0
Updated Aug 19, 2026View on NVD →
Detail

The User Profile Picture plugin by Cozmoslabs is commonly used in WordPress environments to enhance user profiles by allowing users to add or modify profile images. It is favored by website administrators for its ease of integration and customization options within the WordPress framework. The plugin is typically used in a wide range of websites ranging from personal blogs to large corporate websites to provide an enhanced user interface.

This vulnerability pertains to an Information Disclosure issue within the User Profile Picture plugin for WordPress. The REST API endpoint, intended to facilitate user profile image management, inadvertently exposed sensitive user information, such as password hashes and email addresses, to unauthorized users possessing the 'upload_files' capability. This flaw can lead to significant security risks if exploited by malicious attackers.

Technically, the vulnerability arises due to improper access control and an overly permissive implementation of the REST API within the plugin. The endpoint /mpp/v2/get_users is inadequately protected, allowing unauthorized disclosure of sensitive user information. The issue manifests on installations prior to version 2.5.0, where requests can be made to leak confidential user details without stringent access checks.

Exploiting this vulnerability could lead to significant security issues. Attackers with access to sensitive information such as password hashes or user activation keys might perform further attacks such as brute-force attempts or unauthorized impersonation. Insecure systems could be leveraged for data theft, leading to potential reputational damage and loss of user trust.

REFERENCES

Solution Advice
  • Update the User Profile Picture plugin to version 2.5.0 or later to patch the vulnerability.
  • Regularly audit user permissions and limit capabilities to prevent unnecessary access exposure.
  • Ensure proper configuration of REST API permissions and access controls to restrict sensitive information disclosure.
  • Implement monitoring to detect and alert on abnormal API interactions indicating potential exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24170 Scanner - Information Disclosure vulnerability in User Profile Picture S4E