3 results (0.002 seconds)

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 0

01 Feb 2023 — The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset image optimizations. • https://plugins.trac.wordpress.org/browser/kraken-image-optimizer/tags/2.6.6/kraken.php#L705 • CWE-862: Missing Authorization •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

17 Jan 2023 — Missing Authorization vulnerability in Karim Salman Kraken.io Image Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kraken.io Image Optimizer: from n/a through 2.6.7. TheKraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its kraken_media_library_reset_all AJAX action in versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with subscriber-level permi... • https://patchstack.com/database/wordpress/plugin/kraken-image-optimizer/vulnerability/wordpress-kraken-io-image-optimizer-plugin-2-6-7-broken-access-control?_s_id=cve • CWE-862: Missing Authorization •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

23 Sep 2022 — Cross-Site Request Forgery (CSRF) vulnerability in Kraken.io Image Optimizer plugin <= 2.6.5 at WordPress. Una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en el plugin Kraken.io Image Optimizer versiones anteriores a 2.6.5 incluyéndola en WordPress. The Kraken.io Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.5. This is due to missing nonce validation on the kraken_settings_page() function. This makes it possible for unauth... • https://patchstack.com/database/vulnerability/kraken-image-optimizer/wordpress-kraken-io-image-optimizer-plugin-2-6-5-cross-site-request-forgery-csrf-vulnerability/_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •