CVE Database /
CVE-2024-0869
CVE · Medium
CVE-2024-0869 — Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy [instant-images] < 6.1.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-0869
|
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy [instant-images] < 6.1.1 |
Missing Authorization |
Medium
6.5
|
< 6.1.1
|
6.1.1 |
2024-01-29 |
—
|
CVE-2024-0869
The Instant Images plugin before version 6.1.1 contains a broken access control vulnerability that allows unauthenticated or low-privileged users to perform actions reserved for higher-privileged roles due to missing authorization checks and nonce verification. Sean Murphy identified and reported this issue, which was patched in the 6.1.1 release. Users should upgrade to version 6.1.1 or later to eliminate this security risk.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings