PT-2021-3638 · WordPress · Instant Images – One Click Unsplash Uploads

M0Ze

+1

·

Published

2021-06-01

·

Updated

2021-06-11

·

CVE-2021-24334

CVSS v2.0

7.0

High

VectorAV:N/AC:M/Au:S/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions Instant Images – One Click Unsplash Uploads WordPress plugin versions prior to 4.4.0.1
Description The issue is related to the improper validation and sanitization of the unsplash download w and unsplash download h parameter settings in the /wp-admin/upload.php?page=instant-images API endpoint. This leads to a Stored Cross-Site Scripting issue, allowing a remote attacker to perform cross-site scripting attacks. The vulnerability is associated with the lack of protection measures for the web page structure.
Recommendations For Instant Images – One Click Unsplash Uploads WordPress plugin versions prior to 4.4.0.1, update to version 4.4.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the /wp-admin/upload.php?page=instant-images API endpoint until the update is applied. Additionally, avoid using the unsplash download w and unsplash download h parameters in the affected endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03857
CVE-2021-24334

Affected Products

Instant Images – One Click Unsplash Uploads