Back to search
CVE-2015-1376
Published: Jan 28, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20150120 MSA-2015-01: Wordpress Plugin Pixabay Images Multiple Vulnerabilities
mailing-list
x_refsource_FULLDISC
35846
exploit
x_refsource_EXPLOIT-DB
20150119 MSA-2015-01: Wordpress Plugin Pixabay Images Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
[oss-security] 20150125 CVE request: MSA-2015-01: Wordpress Plugin Pixabay Images Multiple Vulnerabilities
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now