VYPR

Manual Image Crop

by WordPress

CVEs (2)

  • CVE-2026-15384MedAug 16, 2026
    risk 0.37cvss 5.7epss 0.00

    The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment images; its only guard passes for any logged-in user. A subscriber-level user can therefore supply an arbitrary…

  • CVE-2015-9426MedSep 26, 2019
    risk 0.30cvss 4.6epss 0.01

    The manual-image-crop plugin before 1.11 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=mic_editor_window postId parameter.