Authorization Bypass Vulnerability in Kraken.io Image Optimizer for WordPress
CVE-2023-0619

6.5MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
1 February 2023

Summary

The Kraken.io Image Optimizer plugin for WordPress has a significant vulnerability that allows authenticated users with subscriber-level permissions and higher to bypass necessary checks on AJAX actions. This flaw enables attackers to reset image optimizations, potentially disrupting the performance and security of websites utilizing the plugin. Users are urged to update to the latest version to safeguard their systems and data.

Affected Version(s)

Kraken.io Image Optimizer * <= 2.6.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Wotschka
.