PT-2024-15878 · WordPress · Instant Images – One Click Image Uploads

Sean Murphy

·

Published

2024-02-05

·

Updated

2024-02-13

·

CVE-2024-0869

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress versions prior to 6.1.1
Description The issue allows unauthorized arbitrary options update due to an insufficient check that neglects to verify whether the updated option belongs to the plugin on the "instant-images/license" API endpoint. This makes it possible for authors and higher to update arbitrary options.
Recommendations For versions up to, and including, 6.1.0, update to version 6.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "instant-images/license" API endpoint until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-0869

Affected Products

Instant Images – One Click Image Uploads