plugin

Wp Retina 2X Vulnerabilities

6 known security issues reported for the Wp Retina 2X WordPress plugin. Most recent disclosed Dec 19, 2023.

3 medium

Running Wp Retina 2X on your site? Check whether your installed version is affected.

Scan your site free

Perfect Images [wp-retina-2x] < 6.4.6

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina).This issue affects Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina): from n/a through 6.4.5.

Affected:
up to 6.4.6
Fixed in:
6.4.6
Disclosed:
Dec 19, 2023

CVE-2023-44982 on NVD →

WP Retina 2x <= 6.4.5 - Sensitive Information Exposure

medium

The Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.5 due to guessable log file names. This makes it possible for unauthenticated attackers to extract sensitive data.

CVSS:
5.3
Affected:
up to 6.4.5
Fixed in:
6.4.6
Disclosed:
Nov 28, 2023

CVE-2023-44982 on NVD →

Perfect Images [wp-retina-2x] < 5.2.3

unknown

[en] The wp-retina-2x plugin before 5.2.3 for WordPress has XSS.

Affected:
up to 5.2.3
Fixed in:
5.2.3
Disclosed:
Aug 22, 2019

CVE-2018-20983 on NVD →

Perfect Images [wp-retina-2x] < 5.2.3

unknown

[en] Cross-site scripting vulnerability in WP Retina 2x prior to version 5.2.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 5.2.3
Fixed in:
5.2.3
Disclosed:
Feb 1, 2018

CVE-2018-0511 on NVD →

Perfect Images <= 5.2.2 - Cross-Site Scripting

medium

The wp-retina-2x plugin before 5.2.3 for WordPress has XSS.

CVSS:
6.1
Affected:
up to 5.2.3
Fixed in:
5.2.3
Disclosed:
Jan 14, 2018

CVE-2018-20983 on NVD →

WP Retina 2x <= 5.2.0 - Cross-Site Scripting

medium

Cross-site scripting vulnerability in WP Retina 2x prior to version 5.2.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
6.1
Affected:
up to 5.2.0
Fixed in:
5.2.2
Disclosed:
Nov 27, 2017

CVE-2018-0511 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database