PT-2021-3638 · WordPress · Instant Images – One Click Unsplash Uploads
M0Ze
+1
·
Published
2021-06-01
·
Updated
2021-06-11
·
CVE-2021-24334
CVSS v2.0
7.0
High
| Vector | AV:N/AC:M/Au:S/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Instant Images – One Click Unsplash Uploads WordPress plugin versions prior to 4.4.0.1
Description
The issue is related to the improper validation and sanitization of the
unsplash download w and unsplash download h parameter settings in the /wp-admin/upload.php?page=instant-images API endpoint. This leads to a Stored Cross-Site Scripting issue, allowing a remote attacker to perform cross-site scripting attacks. The vulnerability is associated with the lack of protection measures for the web page structure.Recommendations
For Instant Images – One Click Unsplash Uploads WordPress plugin versions prior to 4.4.0.1, update to version 4.4.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the
/wp-admin/upload.php?page=instant-images API endpoint until the update is applied. Additionally, avoid using the unsplash download w and unsplash download h parameters in the affected endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Instant Images – One Click Unsplash Uploads