Lucene search

K
wpvulndbDaniel RufWPVDB-ID:03E7C2DC-1C6D-4CFF-AF59-6B41EAD74978
HistoryJun 20, 2022 - 12:00 a.m.

Cache Images < 3.2.1 - Image Upload / Import via CSRF

2022-06-2000:00:00
Daniel Ruf
wpscan.com
5

0.001 Low

EPSS

Percentile

26.5%

The plugin does not implement nonce checks, which could allow attackers to make any logged user upload images via a CSRF attack.

PoC

Allows import of any images with any user level.

CPENameOperatorVersion
cache-imageslt3.2.1

0.001 Low

EPSS

Percentile

26.5%

Related for WPVDB-ID:03E7C2DC-1C6D-4CFF-AF59-6B41EAD74978