PT-2026-73118 · WordPress · Manual-Image-Crop

·

CVE-2026-15384

·

Published

2026-08-16

·

Updated

2026-08-16

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Manual Image Crop versions prior to 1.15
Description The plugin fails to perform capability checks or nonce verification on the authenticated AJAX action used to crop attachment images. Because the current guard allows any logged-in user, a user with subscriber-level privileges can provide an arbitrary attachment ID to overwrite the generated intermediate-size image, such as a thumbnail, and modify its stored metadata, regardless of the media owner. This leads to a cross-user integrity and defacement issue within the Media Library. Additionally, the lack of a nonce makes the action susceptible to Cross-Site Request Forgery (CSRF), a technique where an attacker tricks a victim into performing actions they did not intend to do.
Recommendations Update to version 1.15 or later.

Exploit

Fix

Improper Authentication

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15384

Affected Products

Manual-Image-Crop