CVE-2026-15384Disclosure

LOWCVSS 5.7 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment images; its only guard passes for any logged-in user. A subscriber-level user can therefore supply an arbitrary attachment ID and overwrite that attachment's generated intermediate-size image (for example its thumbnail) and mutate its stored metadata, regardless of who owns the media. This is a cross-user integrity/defacement issue over the Media Library. The action also has no nonce, so it is additionally susceptible to CSRF.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-16: 2Technical Details · 2026-08-16: 208-16
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-15384 The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment … https://www.cve.org/CVERecord?id=CVE-2026-15384 ----- Traducción: CVE-2026-15384 El … https://infoflow.cloud`

    Post summary

    The post announces CVE-2026-15384, noting a missing capability check and nonce verification in the Manual Image Crop WordPress plugin before v1.15. It provides technical details but no evidence of active exploitation, patches, or a PoC.

    00000126
    99 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-15384 The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment … https://www.cve.org/CVERecord?id=CVE-2026-15384

    Post summary

    The post discloses that the Manual Image Crop WordPress plugin lacks capability checks or nonce validation on an AJAX action, raising potential security concerns, but no PoC, exploit, or patch information is provided.

    00000684
    58.0K followersView on X

Explore more