CVE-2015-9426
26.09.2019, 01:15
The manual-image-crop plugin before 1.11 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=mic_editor_window postId parameter.
Vendor | Product | Version |
---|---|---|
manual_image_crop_project | manual_image_crop | 𝑥 < 1.11 |
𝑥
= Vulnerable software versions
References