File Upload Vulnerability in WordPress Pixabay Images Plugin
CVE-2015-1376

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
28 January 2015

Summary

The Pixabay Images plugin for WordPress, prior to version 2.4, contains a vulnerability that fails to properly validate hostnames. This weakness allows remote authenticated users to write and upload files to arbitrary locations by using an upload URL pointing to a host other than pixabay.com. Attackers can leverage this flaw to potentially compromise the integrity of the web server and gain unauthorized access to sensitive data.

References

EPSS Score

70% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.