CVE-2022-2450
14.11.2022, 15:15
The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.Enginsight
Vendor | Product | Version |
---|---|---|
resmush.it | resmush.it_image_optimizer | 𝑥 < 0.4.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration