Splashing Images
Splashing Images has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2018; all 2 are fixed as of September 2026. Their average CVSS score is 7.5, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2018 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Deserialization Of Untrusted Data.
Every one of the 2 issues recorded for Splashing Images has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Nicolas Buzy-Debat. Splashing Images is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.9.31.
CVE-2018-6195Splashing Images <= 2.1 - PHP Object Injection
Read the full analysisVulnerability Records

Splashing Images
Author
janhenckens
Unsplash.com offers stunning photos, free for you to use wherever you want. The Unsplash license allows for photographs to be used for any purpose — both commercial and personal. Blogs, art, book covers, tshirts, and more — paid or unpaid — they’re all allowed under the license. Splashing Images brings these amazing photos to your fingertips, right where you edit your content, in your dashboard. See the latest featured images or search Unsplash to find that perfect image you need for your newest post. Note: this plugin is not affiliated with unsplash.com.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C