Description
The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.
References
https://wpscan.com/vulnerability/1b3ff124-f973-4584-a7d7-26cc404bfe2b
ExploitThird Party Advisory
https://wpscan.com/vulnerability/1b3ff124-f973-4584-a7d7-26cc404bfe2b
ExploitThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
4.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-11-14T14:15:19.260Z
3 years agoLast modified
2025-04-30T18:15:16.803Z
10 months ago