peter bassill · operator
$ cve CVE-2015-1375 JSON

CVE-2015-1375 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 11.9% (pctl 96)

Patch early

A public exploit exists.

Description

pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS11.89% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2015-01-28
Last modified2026-06-17

Affected (1)

VendorProduct
pixabay images projectpixabay images

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD