plugin

Instant Images Vulnerabilities

8 known security issues reported for the Instant Images WordPress plugin. Most recent disclosed May 17, 2024.

1 high 2 medium

Running Instant Images on your site? Check whether your installed version is affected.

Scan your site free

Instant Images &#8211; One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy [instant-images] < 6.1.1

unknown

[en] Improper Privilege Management vulnerability in Darren Cooney Instant Images allows Privilege Escalation.This issue affects Instant Images: from n/a through 6.1.0.

Affected:
up to 6.1.1
Fixed in:
6.1.1
Disclosed:
May 17, 2024

CVE-2024-33569 on NVD →

Instant Images &#8211; One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy [instant-images] < 6.1.1

unknown

[en] The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due to an insufficient check that neglects to verify whether the updated option belongs to the plugin on the instant-images/license REST API endpoint...

Affected:
up to 6.1.1
Fixed in:
6.1.1
Disclosed:
Feb 5, 2024

CVE-2024-0869 on NVD →

Instant Images <= 6.1.0 - Authenticated (Author+) Arbitrary Options Update

high

The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due to an insufficient check that neglects to verify whether the updated option belongs to the plugin on the instant-images/license REST API endpoint in a...

CVSS:
8.8
Affected:
up to 6.1.0
Fixed in:
6.1.1
Disclosed:
Jan 29, 2024

CVE-2024-0869 on NVD →

Instant Images &#8211; One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy [instant-images] < 6.1.1

unknown

The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due to an insufficient check that neglects to verify whether the updated option belongs to the plugin on the instant-images/license REST API endpoint in a...

Affected:
up to 6.1.1
Fixed in:
6.1.1
Disclosed:
Jan 29, 2024

Instant Images &#8211; One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy [instant-images] < 5.2.0

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Darren Cooney Instant Images plugin <= 5.1.0.2 versions.

Affected:
up to 5.2.0
Fixed in:
5.2.0
Disclosed:
Nov 22, 2023

CVE-2023-27451 on NVD →

Instant Images <= 5.1.0.1 - Authenticated (Author+) Server-Side Request Forgery via instant_images_download

medium

The Instant Images plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5.1.0.1via the instant_images_download function. This can allow authenticated attackers, with author-level permissions and above, to make web requests to arbitrary locations originating from the web ap...

CVSS:
5.4
Affected:
up to 5.1.0.1
Fixed in:
5.1.0.2
Disclosed:
Mar 2, 2023

CVE-2023-27451 on NVD →

Instant Images &#8211; One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy [instant-images] < 4.4.0.1

unknown

[en] The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site S...

Affected:
up to 4.4.0.1
Fixed in:
4.4.0.1
Disclosed:
Jun 1, 2021

CVE-2021-24334 on NVD →

Instant Images – One Click Unsplash, Pixabay and Pexels Uploads <= 4.4.0 - Authenticated Stored Cross-Site Scripting

medium

The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site Script...

CVSS:
6.4
Affected:
up to 4.4.0
Fixed in:
4.4.0.1
Disclosed:
May 17, 2021

CVE-2021-24334 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database