plugin

Image Regenerate Select Crop Vulnerabilities

9 known security issues reported for the Image Regenerate Select Crop WordPress plugin. Most recent disclosed Dec 13, 2024.

4 medium

Running Image Regenerate Select Crop on your site? Check whether your installed version is affected.

Scan your site free

Image Regenerate &amp; Select Crop [image-regenerate-select-crop] < 7.2.0

unknown

[en] Missing Authorization vulnerability in Iulia Cazan Image Regenerate & Select Crop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Regenerate & Select Crop: from n/a through 7.1.0.

Affected:
up to 7.2.0
Fixed in:
7.2.0
Disclosed:
Dec 13, 2024

CVE-2023-36680 on NVD →

Image Regenerate &amp; Select Crop [image-regenerate-select-crop] < 7.3.1

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Iulia Cazan Image Regenerate & Select Crop.This issue affects Image Regenerate & Select Crop: from n/a through 7.3.0.

Affected:
up to 7.3.1
Fixed in:
7.3.1
Disclosed:
Nov 30, 2023

CVE-2023-46820 on NVD →

Image Regenerate & Select Crop <= 7.3.0 - Sensitive Information Exposure

medium

The Image Regenerate & Select Crop plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.3.0 via the log file directory. This can allow unauthenticated attackers to extract sensitive data if directory indexing is enabled or if they are able to determine the log file fo...

CVSS:
5.3
Affected:
up to 7.3.0
Fixed in:
7.3.1
Disclosed:
Oct 9, 2023

CVE-2023-46820 on NVD →

Image Regenerate &amp; Select Crop [image-regenerate-select-crop] < 7.3.0

unknown

The Image Regenerate & Select Crop plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.3.0 via the log file directory. This can allow unauthenticated attackers to extract sensitive data if directory indexing is enabled or if they are able to determine the log file fo...

Affected:
up to 7.3.0
Fixed in:
7.3.0
Disclosed:
Oct 9, 2023

Image Regenerate & Select Crop <= 7.1.0 - Missing Authorization

medium

The Image Regenerate & Select Crop plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple functions in versions up to, and including, 7.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized...

CVSS:
5.4
Affected:
up to 7.1.0
Fixed in:
7.2.0
Disclosed:
Jul 4, 2023

CVE-2023-36680 on NVD →

Image Regenerate & Select Crop <= 7.1.0 - Missing Authorization on multiple AJAX actions

medium

The Image Regenerate & Select Crop plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to missing capability and nonce checks on multiple AJAX functions in versions up to, and including, 7.1.0. This makes it possible for authenticated attackers to bulk rename, process, and delete im...

CVSS:
6.5
Affected:
up to 7.2.0
Fixed in:
7.2.0
Disclosed:
Jul 1, 2023

Image Regenerate & Select Crop <= 7.1.0 - Cross-Site Request Forgery on multiple AJAX actions

medium

The Image Regenerate & Select Crop plugin for WordPress is vulnerable to cross-site request forgery due to missing nonce checks on multiple AJAX functions in versions up to, and including, 7.1.0. This makes it possible for authenticated attackers to bulk rename, process, and delete image files.

CVSS:
6.5
Affected:
up to 7.2.0
Fixed in:
7.2.0
Disclosed:
Jul 1, 2023

Image Regenerate &amp; Select Crop [image-regenerate-select-crop] < 7.2.0

unknown

The Image Regenerate & Select Crop plugin for WordPress is vulnerable to cross-site request forgery due to missing nonce checks on multiple AJAX functions in versions up to, and including, 7.1.0. This makes it possible for authenticated attackers to bulk rename, process, and delete image files.

Affected:
up to 7.2.0
Fixed in:
7.2.0
Disclosed:
Jul 1, 2023

Image Regenerate &amp; Select Crop [image-regenerate-select-crop] < 7.2.0

unknown

The Image Regenerate & Select Crop plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to missing capability and nonce checks on multiple AJAX functions in versions up to, and including, 7.1.0. This makes it possible for authenticated attackers to bulk rename, process, and delete im...

Affected:
up to 7.2.0
Fixed in:
7.2.0
Disclosed:
Jul 1, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database