Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51728 | The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the gky_image_uploader_main_function() function. This makes it possible for unauthenticated attackers to delete arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. |
Fri, 31 Jan 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ivanm
Ivanm wp Image Uploader |
|
| CPEs | cpe:2.3:a:ivanm:wp_image_uploader:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Ivanm
Ivanm wp Image Uploader |
Thu, 30 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jan 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the gky_image_uploader_main_function() function. This makes it possible for unauthenticated attackers to delete arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Title | WP Image Uploader <= 1.0.1 - Cross-Site Request Forgery to Arbitrary File Deletion | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:57:33.515Z
Reserved: 2025-01-24T14:31:25.315Z
Link: CVE-2024-13707
Updated: 2025-01-30T14:41:12.219Z
Status : Analyzed
Published: 2025-01-30T14:15:36.363
Modified: 2025-01-31T18:12:42.913
Link: CVE-2024-13707
No data.
OpenCVE Enrichment
No data.
EUVD