plugin

Pixabay Images Vulnerabilities

5 known security issues reported for the Pixabay Images WordPress plugin. Most recent disclosed Jun 17, 2025.

1 critical 3 high 1 medium

Running Pixabay Images on your site? Check whether your installed version is affected.

Scan your site free

Pixabay Images <= 3.4 - Authenticated (Author+) Arbitrary File Upload

high

The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pixabay_upload function in all versions up to, and including, 3.4. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected...

CVSS:
8.8
Affected:
up to 3.4
Fix:
No patched version reported
Disclosed:
Jun 17, 2025

CVE-2025-4413 on NVD →

Pixabay Images <= 2.0 - Authentication Bypass to Arbitrary File Upload

critical

pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.

CVSS:
9.8
Affected:
up to 2.0
Fixed in:
2.4
Disclosed:
Jan 19, 2015

CVE-2015-1375 on NVD →

Pixabay Images <= 2.3 - Arbitrary File Upload

high

pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.

CVSS:
8.8
Affected:
up to 2.3
Fixed in:
2.4
Disclosed:
Jan 19, 2015

CVE-2015-1376 on NVD →

Pixabay Images <= 2.3 - Directory Traversal

high

Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbitrary files via a .. (dot dot) in the q parameter.

CVSS:
7.5
Affected:
up to 2.3
Fixed in:
2.4
Disclosed:
Jan 19, 2015

CVE-2015-1365 on NVD →

Pixabay Images <= 2.3 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the image_user parameter.

CVSS:
6.1
Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Jan 19, 2015

CVE-2015-1366 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database