VDB
Sign up
—

PYSEC-2026-733

Plone allows remote users to modify arbitrary portraits

Quick fix

PYSEC-2026-733 — plone: upgrade to the fixed version with the command below.

pip install --upgrade 'plone>=2.0.6'

Details

Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/plone
Introduced in: 0Fixed in: 2.0.6
Fixpip install --upgrade 'plone>=2.0.6'

References