PT-2026-103038 · WordPress · Image Optimizer
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Image Optimizer WordPress plugin versions prior to 1.7.7
Description
The plugin fails to enforce intended capability checks on several read REST routes. This allows any authenticated user to access attachment metadata and site-wide statistics, information that should be restricted to users with administrator privileges.
Recommendations
Update the plugin to version 1.7.7 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Image Optimizer