Image Compressor & Optimizer - iLoveIMG <= 1.0.5 - Authenticated (Administrator+) PHP Object Injection
highThe Image Compressor & Optimizer – iLoveIMG plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 1.0.6 (exclusive) via deserialization of untrusted input. This makes it possible for authenticated attackers, with admin access or higher to inject a PHP Object. No POP chain is present in the vu...
- CVSS:
- 7.2
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Nov 13, 2023