CVE-2026-0684
CP Image Store with Slideshow <= 1.1.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Product Import
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9 due to a logic error in the 'cpis_admin_init' function's permission check. This makes it possible for authenticated attackers, with Contributor-level access and above, to import arbitrary products via XML, if the XML file has already been uploaded to the server.
| CWE | CWE-863 |
| Vendor | codepeople |
| Product | cp image store with slideshow |
| Published | Jan 13, 2026 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for codepeople cp image store with slideshow
Be the first to know when new medium vulnerabilities affecting codepeople cp image store with slideshow are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
codepeople / CP Image Store with Slideshow
0 โค 1.1.9
References
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/28e48604-2aaf-4e02-9b1e-cebf5f0bfcf7?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/cp-image-store/tags/1.1.9/cp-image-store.php#L826 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3434716/
Credits
Kazuma Matsumoto