Image Regenerate & Select Crop [image-regenerate-select-crop] < 7.2.0
unknown
[en] Missing Authorization vulnerability in Iulia Cazan Image Regenerate & Select Crop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Regenerate & Select Crop: from n/a through 7.1.0.
- Affected:
- up to 7.2.0
- Fixed in:
- 7.2.0
- Disclosed:
- Dec 13, 2024
CVE-2023-36680 on NVD →
Image Regenerate & Select Crop [image-regenerate-select-crop] < 7.3.1
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Iulia Cazan Image Regenerate & Select Crop.This issue affects Image Regenerate & Select Crop: from n/a through 7.3.0.
- Affected:
- up to 7.3.1
- Fixed in:
- 7.3.1
- Disclosed:
- Nov 30, 2023
CVE-2023-46820 on NVD →
Image Regenerate & Select Crop <= 7.3.0 - Sensitive Information Exposure
medium
The Image Regenerate & Select Crop plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.3.0 via the log file directory. This can allow unauthenticated attackers to extract sensitive data if directory indexing is enabled or if they are able to determine the log file fo...
- CVSS:
- 5.3
- Affected:
- up to 7.3.0
- Fixed in:
- 7.3.1
- Disclosed:
- Oct 9, 2023
CVE-2023-46820 on NVD →
Image Regenerate & Select Crop [image-regenerate-select-crop] < 7.3.0
unknown
The Image Regenerate & Select Crop plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.3.0 via the log file directory. This can allow unauthenticated attackers to extract sensitive data if directory indexing is enabled or if they are able to determine the log file fo...
- Affected:
- up to 7.3.0
- Fixed in:
- 7.3.0
- Disclosed:
- Oct 9, 2023
Image Regenerate & Select Crop <= 7.1.0 - Missing Authorization
medium
The Image Regenerate & Select Crop plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple functions in versions up to, and including, 7.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized...
- CVSS:
- 5.4
- Affected:
- up to 7.1.0
- Fixed in:
- 7.2.0
- Disclosed:
- Jul 4, 2023
CVE-2023-36680 on NVD →
Image Regenerate & Select Crop <= 7.1.0 - Missing Authorization on multiple AJAX actions
medium
The Image Regenerate & Select Crop plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to missing capability and nonce checks on multiple AJAX functions in versions up to, and including, 7.1.0. This makes it possible for authenticated attackers to bulk rename, process, and delete im...
- CVSS:
- 6.5
- Affected:
- up to 7.2.0
- Fixed in:
- 7.2.0
- Disclosed:
- Jul 1, 2023
Image Regenerate & Select Crop <= 7.1.0 - Cross-Site Request Forgery on multiple AJAX actions
medium
The Image Regenerate & Select Crop plugin for WordPress is vulnerable to cross-site request forgery due to missing nonce checks on multiple AJAX functions in versions up to, and including, 7.1.0. This makes it possible for authenticated attackers to bulk rename, process, and delete image files.
- CVSS:
- 6.5
- Affected:
- up to 7.2.0
- Fixed in:
- 7.2.0
- Disclosed:
- Jul 1, 2023
Image Regenerate & Select Crop [image-regenerate-select-crop] < 7.2.0
unknown
The Image Regenerate & Select Crop plugin for WordPress is vulnerable to cross-site request forgery due to missing nonce checks on multiple AJAX functions in versions up to, and including, 7.1.0. This makes it possible for authenticated attackers to bulk rename, process, and delete image files.
- Affected:
- up to 7.2.0
- Fixed in:
- 7.2.0
- Disclosed:
- Jul 1, 2023
Image Regenerate & Select Crop [image-regenerate-select-crop] < 7.2.0
unknown
The Image Regenerate & Select Crop plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to missing capability and nonce checks on multiple AJAX functions in versions up to, and including, 7.1.0. This makes it possible for authenticated attackers to bulk rename, process, and delete im...
- Affected:
- up to 7.2.0
- Fixed in:
- 7.2.0
- Disclosed:
- Jul 1, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database