Image Zoom [image-zoom] <= 1.8.8 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in SedLex Image Zoom.This issue affects Image Zoom: from n/a through 1.8.8.
- Affected:
- up to 1.8.8
- Fix:
- No patched version reported
- Disclosed:
- Jan 17, 2024
CVE-2022-41619 on NVD →
Image Zoom <= 1.8.8 - Missing Authorization
medium
The Image Zoom plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several of its AJAX functions in versions up to, and including, 1.8.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke them leading to translation mod...
- CVSS:
- 6.5
- Affected:
- up to 1.8.8
- Fix:
- No patched version reported
- Disclosed:
- Sep 21, 2022
CVE-2022-41619 on NVD →
Image Zoom <= 1.8.8 - Cross-Site Request Forgery
high
The Image Zoom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.8. This is due to missing or incorrect nonce validation on all of the plugin's AJAX endpoints. This makes it possible for unauthenticated attackers to invoke the functions associated with them, via forg...
- CVSS:
- 8.8
- Affected:
- up to 1.8.8
- Fix:
- No patched version reported
- Disclosed:
- Sep 20, 2022
Image Zoom [image-zoom] <= 1.8.8 (unfixed + closed)
unknown
The Image Zoom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.8. This is due to missing or incorrect nonce validation on all of the plugin's AJAX endpoints. This makes it possible for unauthenticated attackers to invoke the functions associated with them, via forg...
- Affected:
- up to 1.8.8
- Fix:
- No patched version reported
- Disclosed:
- Sep 20, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database