Extension WordPress

Vulnérabilités Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy

Cette page rassemble les failles publiées pour Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy, leurs plages de versions affectées et les correctifs signalés dans la base locale.

3Vulnérabilités
0Critiques
3Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy

3 fiches

CVE-2024-0869 Élevée · 8,8
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy

Instant Images <= 6.1.0 – Authenticated (Author+) Arbitrary Options Update

The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due to an insufficient check that neglects to verify whether the updated option belongs…

Versions affectées

*-6.1.0

Correctif

6.1.1

Publication

29/01/2024

CVE-2023-27451 Moyenne · 5,4
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy

Instant Images <= 5.1.0.1 – Authenticated (Author+) Server-Side Request Forgery via instant_images_download

The Instant Images plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5.1.0.1via the instant_images_download function. This can allow authenticated attackers, with author-level permissions and above, to make web requests to arbitrary…

Versions affectées

*-5.1.0.1

Correctif

5.1.0.2

Publication

02/03/2023

CVE-2021-24334 Moyenne · 6,4
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy

Instant Images – One Click Unsplash, Pixabay and Pexels Uploads <= 4.4.0 – Authenticated Stored Cross-Site Scripting

The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site…

Versions affectées

*-4.4.0

Correctif

4.4.0.1

Publication

17/05/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités