The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due to an insufficient check that neglects to verify whether the updated option belongs to the plugin on the instant-images/license REST API endpoint in all versions up to, and including, 6.1.0. This makes it possible for authors and higher to update arbitrary options. CVE-2024-33569 appears to be a duplicate of this issue.
References
Configurations
Configuration 1 (hide)
|
History
08 Apr 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-862 | |
| Summary | (en) The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due to an insufficient check that neglects to verify whether the updated option belongs to the plugin on the instant-images/license REST API endpoint in all versions up to, and including, 6.1.0. This makes it possible for authors and higher to update arbitrary options. CVE-2024-33569 appears to be a duplicate of this issue. |
21 Nov 2024, 08:47
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://plugins.trac.wordpress.org/browser/instant-images/tags/6.1.0/api/license.php#L91 - Product | |
| References | () https://plugins.trac.wordpress.org/changeset/3027110/instant-images/tags/6.1.1/api/license.php - Patch | |
| References | () https://wordpress.org/plugins/instant-images/ - Product | |
| References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/17941fbb-c5da-4f5c-a617-3792eb4ef395?source=cve - Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
13 Feb 2024, 19:45
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://plugins.trac.wordpress.org/browser/instant-images/tags/6.1.0/api/license.php#L91 - Product | |
| References | () https://wordpress.org/plugins/instant-images/ - Product | |
| References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/17941fbb-c5da-4f5c-a617-3792eb4ef395?source=cve - Third Party Advisory | |
| References | () https://plugins.trac.wordpress.org/changeset/3027110/instant-images/tags/6.1.1/api/license.php - Patch | |
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:connekthq:instant_images_-_one_click_unsplash_uploads:*:*:*:*:*:wordpress:*:* | |
| First Time |
Connekthq instant Images - One Click Unsplash Uploads
Connekthq |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
05 Feb 2024, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-02-05 22:16
Updated : 2026-04-08 17:17
NVD link : CVE-2024-0869
Mitre link : CVE-2024-0869
CVE.ORG link : CVE-2024-0869
JSON object : View
Products Affected
connekthq
- instant_images_-_one_click_unsplash_uploads
CWE
