CVE-2015-1376

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
28 January 2015

Summary

pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.

References

EPSS Score

82% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.