Pixabay Images <= 3.4 - Authenticated (Author+) Arbitrary File Upload
high
The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pixabay_upload function in all versions up to, and including, 3.4. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected...
- CVSS:
- 8.8
- Affected:
- up to 3.4
- Fix:
- No patched version reported
- Disclosed:
- Jun 17, 2025
CVE-2025-4413 on NVD →
Pixabay Images <= 2.0 - Authentication Bypass to Arbitrary File Upload
critical
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.
- CVSS:
- 9.8
- Affected:
- up to 2.0
- Fixed in:
- 2.4
- Disclosed:
- Jan 19, 2015
CVE-2015-1375 on NVD →
Pixabay Images <= 2.3 - Arbitrary File Upload
high
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.
- CVSS:
- 8.8
- Affected:
- up to 2.3
- Fixed in:
- 2.4
- Disclosed:
- Jan 19, 2015
CVE-2015-1376 on NVD →
Pixabay Images <= 2.3 - Directory Traversal
high
Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbitrary files via a .. (dot dot) in the q parameter.
- CVSS:
- 7.5
- Affected:
- up to 2.3
- Fixed in:
- 2.4
- Disclosed:
- Jan 19, 2015
CVE-2015-1365 on NVD →
Pixabay Images <= 2.3 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the image_user parameter.
- CVSS:
- 6.1
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Jan 19, 2015
CVE-2015-1366 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database