PT-2026-47235 · Background Image Cropper · Background Image Cropper

Milad Karimi

·

Published

2026-06-08

·

Updated

2026-06-08

·

CVE-2024-58348

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitrary files by accessing the ups.php endpoint. Attackers can upload PHP files through the file upload form in the plugin directory to execute arbitrary code on the server.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-58348

Affected Products

Background Image Cropper