Extension WordPress
Vulnérabilités Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
Cette page rassemble les failles publiées pour Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
3 fiches
Instant Images <= 6.1.0 – Authenticated (Author+) Arbitrary Options Update
The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due to an insufficient check that neglects to verify whether the updated option belongs…
*-6.1.0
6.1.1
29/01/2024
Instant Images <= 5.1.0.1 – Authenticated (Author+) Server-Side Request Forgery via instant_images_download
The Instant Images plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5.1.0.1via the instant_images_download function. This can allow authenticated attackers, with author-level permissions and above, to make web requests to arbitrary…
*-5.1.0.1
5.1.0.2
02/03/2023
Instant Images – One Click Unsplash, Pixabay and Pexels Uploads <= 4.4.0 – Authenticated Stored Cross-Site Scripting
The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site…
*-4.4.0
4.4.0.1
17/05/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.