Pixabay Images <= 2.0 - Authentication Bypass to Arbitrary File Upload
2015-01-19 00:00
Mogwai, IT-Sicherheitsberatung MunichStrategic Overview
StatusPatched in 2.4
Affected PluginPixabay Images
Affected Version
<= 2.0CVSS9.8Critical
CVE
CVE-2015-1375Vulnerability Overview
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.
Technical Analysis
REMEDIATION: Update to version 2.4, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C