4
CVSSv2

CVE-2015-1376

Published: 28/01/2015 Updated: 09/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

pixabay-images.php in the Pixabay Images plugin prior to 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pixabay images project pixabay images

Exploits

Mogwai Security Advisory MSA-2015-01 ---------------------------------------------------------------------- Title: WP Pixarbay Images Multiple Vulnerabilities Product: Pixarbay Images (Wordpress Plugin) Affected versions: 23 Impact: high Remote: yes Product link: wordpressorg/plugins/ ...