cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forauto-attachments auto-attachments

Direction: ascending
Jun 06, 2024

Auto Attachments # a144649f8f24fd52a3c3d77390d79c9691c671b8

Application

Auto Attachments

Date
Sep 19, 2011
Research Description
Auto Attachments [auto-attachments] < 0.4 WordPress Multiple Plugin - timthumb.php Vulnerabilites This Multiple plugin is prone to a timthumb.php library vulnerabilities. The attacker controls domain such as blogger.com by hosting a malicious GIF file with code that is appended to the end on. Then provides it to the script through the src GET parameter. Upgrade the plugin.
Affected versions
max 0.4.
Status
vulnerable
Jun 15, 2025

Auto Attachments # CVE-2025-6012

CVE, Research URL

CVE-2025-6012

Application

Auto Attachments

Date
Jun 13, 2025
Research Description
The Auto Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Affected versions
max 1.8.5.
Status
vulnerable