Cross-Site Request Forgery in Image Optimizer Plugin for WordPress
CVE-2025-12190
4.3MEDIUM
What is CVE-2025-12190?
The Image Optimizer by wps.sk plugin for WordPress is susceptible to Cross-Site Request Forgery attacks due to improper nonce validation in the imagopby_ajax_optimize_gallery() function. This vulnerability allows unauthenticated attackers to execute bulk optimization requests if they can deceive an administrator into clicking a malicious link, potentially compromising the site's integrity.
Affected Version(s)
Image Optimizer by wps.sk * <= 1.2.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Sarawut Poolkhet