Description

The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9 due to a logic error in the 'cpis_admin_init' function's permission check. This makes it possible for authenticated attackers, with Contributor-level access and above, to import arbitrary products via XML, if the XML file has already been uploaded to the server.

INFO

Published Date :

2026-01-13T13:49:12.628Z

Last Modified :

2026-01-13T14:13:53.871Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2026-0684 vulnerability.

Vendors Products
Codepeople
  • Cp Image Store With Slideshow
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact