CVE-2026-15384: Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOR

Published Aug 16, 2026
·
Updated

The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment images; its only guard passes for any logged-in user. A subscriber-level user can therefore supply an arbitrary attachment ID and overwrite that attachment's generated intermediate-size image (for example its thumbnail) and mutate its stored metadata, regardless of who owns the media. This is a cross-user integrity/defacement issue over the Media Library. The action also has no nonce, so it is additionally susceptible to CSRF.

Affected Software

1 affected component
WordPress plugin Manual Image Crop<1.15

Event History

Aug 16, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-15384?

CVE-2026-15384 has a risk score of 48, indicating a medium threat level.

2

How do I fix CVE-2026-15384?

To fix CVE-2026-15384, update the Manual Image Crop WordPress plugin to version 1.15 or later.

3

What type of vulnerability is CVE-2026-15384?

CVE-2026-15384 is identified as an IDOR vulnerability, allowing unauthorized image overwrites.

4

Who is affected by CVE-2026-15384?

CVE-2026-15384 affects websites using the Manual Image Crop plugin version before 1.15 with authenticated users having subscriber roles.

5

What can attackers do with CVE-2026-15384?

Attackers can exploit CVE-2026-15384 to overwrite arbitrary image attachments by supplying their IDs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203