What is CVE-2026-15384?
This vulnerability affects the Manual Image Crop WordPress plugin before version 1.15, which lacks capability checks and nonce verification on an AJAX action for cropping images. Any authenticated subscriber-level user can manipulate arbitrary attachment IDs to crop images without proper authorization. Immediate update to the latest plugin version is strongly recommended.
Azərbaycanca: Bu boşluq Manual Image Crop WordPress plaginin 1.15-dən əvvəlki versiyalarına təsir edir. Autentifikasiya olunmuş istənilən abunəçi səviyyəli istifadəçi xüsusi AJAX əməliyyatı vasitəsilə icazə yoxlanışı olmadan ixtiyari şəkil fayllarının kəsilməsinə səbəb ola bilər. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What user level does CVE-2026-15384 affect in the Manual Image Crop plugin?
Any authenticated subscriber-level user can exploit this vulnerability.
What is the best mitigation for CVE-2026-15384?
It is strongly recommended to immediately update the Manual Image Crop plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.