Products

Showing 1 vulnerability on this page

Signals CISA KEV Ransomware Nuclei
imagestowebp_project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Images to WebP < 1.9 - Authenticated Local File Inclusion

The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue

CWE-22Nov 23, 20211 related artifact
CVSS7.5v3.1EPSS5.03%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX