pixabay-images.php in the Pixabay Images plugin before 2...
Moderate severity
Unreviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Jan 28, 2015
Published to the GitHub Advisory Database
May 14, 2022
Last updated
Feb 2, 2023
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.
References