CVE-2026-15384
Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment images; its only guard passes for any logged-in user. A subscriber-level user can therefore supply an arbitrary attachment ID and overwrite that attachment's generated intermediate-size image (for example its thumbnail) and mutate its stored metadata, regardless of who owns the media. This is a cross-user integrity/defacement issue over the Media Library. The action also has no nonce, so it is additionally susceptible to CSRF.
| Vendor | unknown |
| Product | manual image crop |
| Published | Aug 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown manual image crop
Be the first to know when new unknown vulnerabilities affecting unknown manual image crop are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Manual Image Crop
0 < 1.15
References
Credits
Shivamani Vastrala WPScan