WP Image Zoom [wp-image-zoooom] < 1.47.1
unknown
[en] The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() function, leading to a local file inclusion issue in the admin dashboard
- Affected:
- up to 1.47.1
- Fixed in:
- 1.47.1
- Disclosed:
- Jul 19, 2021
CVE-2021-24447 on NVD →
WP Image Zoom <= 1.46 - Local File Inclusion
medium
The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() function, leading to a local file inclusion issue in the admin dashboard
- CVSS:
- 5.3
- Affected:
- up to 1.46
- Fixed in:
- 1.47.1
- Disclosed:
- Jun 23, 2021
CVE-2021-24447 on NVD →
WP Image Zoom [wp-image-zoooom] < 1.24
unknown
[en] WP Image Zoom version 1.23 contains a Incorrect Access Control vulnerability in AJAX settings that can result in allows anybody to cause denial of service. This attack appear to be exploitable via Can be triggered intentionally (or unintentionally via CSRF) by any logged in user. This vulnerability appears to have...
- Affected:
- up to 1.24
- Fixed in:
- 1.24
- Disclosed:
- Jun 26, 2018
CVE-2018-1000510 on NVD →
WP Image Zoom [wp-image-zoooom] < 1.24
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Tom Adams in WordPress WP Image Zoom plugin (versions <=1.23).
- Affected:
- up to 1.24
- Fixed in:
- 1.24
- Disclosed:
- Apr 12, 2018
WP Image Zoom <= 1.23 - Cross-Site Request Forgery to Denial of Service
medium
WP Image Zoom version 1.23 contains a Incorrect Access Control vulnerability in AJAX settings that can result in allows anybody to cause denial of service. This attack appear to be exploitable via Can be triggered intentionally (or unintentionally via CSRF) by any logged in user. This vulnerability appears to have been...
- CVSS:
- 6.5
- Affected:
- up to 1.23
- Fixed in:
- 1.24
- Disclosed:
- Mar 29, 2018
CVE-2018-1000510 on NVD →
WP Image Zoom [wp-image-zoooom] < 1.1.1
unknown
WP Image Zoom plugin is prone to multiple vulnerabilities that allow anybody to upload .jpg files because of affected "div_img.php" file.
Update the plugin.
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- Jun 8, 2015
WP Image Zoom [wp-image-zoooom] < 1.0.4
unknown
This plugin is prone to download.php file upload PHP code execution vulnerability.
Update plugin.
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
- Disclosed:
- May 15, 2015
WP Image Zoom [wp-image-zoooom] < 1.1
unknown
Because of this vulnerability, attackers can compromise the application, access or modify data. zoom.php id parameter is vulnerable.
Update plugin.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- May 15, 2015
WP Image Zoom [wp-image-zoooom] < 1.0.4
unknown
Wp Image Zoom plugin is prone to a remote file disclosure vulnerability. It allows an attacker to view local files in the context of the web server process, that may aid in further attacks.
Update the plugin.
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
- Disclosed:
- Jun 18, 2012
WP Image Zoom [wp-image-zoooom] < 1.24
unknown
The WP Image Zoom WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.
- Affected:
- up to 1.24
- Fixed in:
- 1.24
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database