Pixabay Images <= 2.0 - Authentication Bypass to Arbitrary File Upload

Strategic Overview

Status
Patched in 2.4
Affected PluginPixabay Images
Affected Version<= 2.0
CVSS9.8Critical
CVECVE-2015-1375
View all Pixabay Images vulnerabilities

Vulnerability Overview

pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.

Technical Analysis

REMEDIATION: Update to version 2.4, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C