
🚨*CVE* CVE-2026-15384 The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment … https://www.cve.org/CVERecord?id=CVE-2026-15384 ----- Traducción: CVE-2026-15384 El … https://infoflow.cloud`
Post summary
The post announces CVE-2026-15384, noting a missing capability check and nonce verification in the Manual Image Crop WordPress plugin before v1.15. It provides technical details but no evidence of active exploitation, patches, or a PoC.

