CVE Published: 14/11/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: WPScan |
Vendor: Unknown |
Product: reSmush.it : the only free Image Optimizer & compress plugin Status : PUBLISHED
CVE-2022-2450 Description
The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.