WordPress 插件 Manual Image Crop 在 1.15 版本之前,在对用于裁剪附件图片的已认证 AJAX 操作中没有执行任何权限检查或 Nonce 验证;其仅有的防护机制允许任何已登录用户通过验证。因此,具有订阅者(subscriber)级别权限的用户可以传入任意的附件 ID,从而覆盖该附件生成的中间尺寸图片(例如其缩略图),并篡改其存储的元数据,无论该媒体文件归属于哪位用户。这构成了媒体库中的跨用户完整性破坏/页面篡改问题。此外,该操作未设置 Nonce,因此还容易受到跨站请求伪造(CSRF)
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Manual Image Crop | < 1.15 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Manual Image Crop | 0 ~ 1.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19726 | Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure | |
| CVE-2026-19728 | Extra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File Di | |
| CVE-2026-19725 | WPvivid Backup & Migration < 0.9.131 - Unauthenticated Path Traversal via send_to_site_con | |
| CVE-2026-18653 | WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter | |
| CVE-2026-19712 | Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description | |
| CVE-2026-19613 | ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source | |
| CVE-2026-19717 | CatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST API | |
| CVE-2026-19714 | Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Au | |
| CVE-2026-19711 | Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount W | |
| CVE-2026-13712 | Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL | |
| CVE-2026-17533 | All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Cod |
No comments yet