CVE-2015-1376

Pixabay Images <2.4 - Code Injection

Title source: llm

Description

pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.

Exploits (2)

exploitdb WORKING POC
by Hans-Martin Muench · textwebappsphp
https://www.exploit-db.com/exploits/35846
metasploit WORKING POC EXCELLENT
by h0ng10 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/wp_pixabay_images_upload.rb

Scores

EPSS 0.7051
EPSS Percentile 98.7%

Details

CWE
CWE-284
Status published
Products (1)
pixabay_images_project/pixabay_images < 2.3
Published Jan 28, 2015
Tracked Since Feb 18, 2026