Loading vulnerability details…
CVSS v3.1
N/A
EPSS
12.25%
Published
Jan 28, 2015
Modified
May 6, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.
Weaknesses (CWE)
Affected Products (1)
References (14)