Cross-Site Request Forgery in Image Optimizer Plugin for WordPress
CVE-2025-12190
4.3MEDIUM
What is CVE-2025-12190?
The Image Optimizer by wps.sk plugin for WordPress is susceptible to Cross-Site Request Forgery attacks due to improper nonce validation in the imagopby_ajax_optimize_gallery() function. This vulnerability allows unauthenticated attackers to execute bulk optimization requests if they can deceive an administrator into clicking a malicious link, potentially compromising the site's integrity.
Affected Version(s)
Image Optimizer by wps.sk * <= 1.2.0