PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter
mediumThe PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.2 via the move_image_on_server function. This makes it possible for authenticated attackers, with author-level access and above, to write files with attacker-controlled content to ar...
- CVSS:
- 6.5
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.3
- Disclosed:
- Jun 29, 2026