๐Ÿ” CVE Alert

CVE-2026-15384

UNKNOWN 0.0

Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment images; its only guard passes for any logged-in user. A subscriber-level user can therefore supply an arbitrary attachment ID and overwrite that attachment's generated intermediate-size image (for example its thumbnail) and mutate its stored metadata, regardless of who owns the media. This is a cross-user integrity/defacement issue over the Media Library. The action also has no nonce, so it is additionally susceptible to CSRF.

Vendor unknown
Product manual image crop
Published Aug 16, 2026
Stay Ahead of the Next One

Get instant alerts for unknown manual image crop

Be the first to know when new unknown vulnerabilities affecting unknown manual image crop are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Manual Image Crop
0 < 1.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/706d0b6a-d136-4317-a767-33bcab3b041c/

Credits

Shivamani Vastrala WPScan