plugin

Image Optimizer Wd Vulnerabilities

9 known security issues reported for the Image Optimizer Wd WordPress plugin. Most recent disclosed Aug 16, 2023.

3 medium 1 low

Running Image Optimizer Wd on your site? Check whether your installed version is affected.

Scan your site free

Image Optimizer by 10web &#8211; Image Optimizer and Compression plugin [image-optimizer-wd] < 1.0.27

unknown

[en] The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicki...

Affected:
up to 1.0.27
Fixed in:
1.0.27
Disclosed:
Aug 16, 2023

CVE-2023-2122 on NVD →

Image Optimizer by 10web &#8211; Image Optimizer and Compression plugin [image-optimizer-wd] < 1.0.27

unknown

[en] The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

Affected:
up to 1.0.27
Fixed in:
1.0.27
Disclosed:
May 30, 2023

CVE-2023-2117 on NVD →

Image Optimizer by 10web <= 1.0.26 - Authenticated(Administator+) Directory Traversal

low

The Image Optimizer by 10web plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.0.26 via the dir parameter in the get_subdirs AJAX function. This allows authenticated attackers with administrator-level permissions or above to view the directory structure of arbitrary folders o...

CVSS:
2.7
Affected:
up to 1.0.26
Fixed in:
1.0.27
Disclosed:
May 2, 2023

CVE-2023-2117 on NVD →

Image Optimizer WD <= 1.0.26 - Reflected Cross-Site Scripting

medium

The Image Optimizer WD plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'iowd_tabs_active' parameter in versions up to, and including, 1.0.26 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

CVSS:
6.1
Affected:
up to 1.0.26
Fixed in:
1.0.27
Disclosed:
Apr 26, 2023

CVE-2023-2122 on NVD →

Image Optimizer WD <= 1.0.26 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Image Optimizer WD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.0.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

CVSS:
4.4
Affected:
up to 1.0.26
Fixed in:
1.0.27
Disclosed:
Apr 21, 2023

Image Optimizer by 10web &#8211; Image Optimizer and Compression plugin [image-optimizer-wd] < 1.0.27

unknown

The Image Optimizer WD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.0.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

Affected:
up to 1.0.27
Fixed in:
1.0.27
Disclosed:
Apr 21, 2023

Image Optimizer by 10web &#8211; Image Optimizer and Compression plugin [image-optimizer-wd] < 1.0.26

unknown

Update the WordPress Image Optimizer by 10web plugin to the latest available version (at least 1.0.26). An unknown person discovered and reported this Directory Traversal vulnerability in WordPress Image Optimizer by 10web Plugin. This could allow a malicious actor to see all files in a given directory or determine if...

Affected:
up to 1.0.26
Fixed in:
1.0.26
Disclosed:
Apr 20, 2023

Image Optimizer by 10web <= 1.0.25 - Directory Traversal to Information Exposure

medium

The Image Optimizer by 10web plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.0.25 via the dir parameter in the get_subdirs AJAX function. This allows authenticated attackers with subscriber-level permissions or above to view the directory structure of arbitrary folders on t...

CVSS:
4.3
Affected:
up to 1.0.26
Fixed in:
1.0.26
Disclosed:
Apr 19, 2023

Image Optimizer by 10web &#8211; Image Optimizer and Compression plugin [image-optimizer-wd] < 1.0.26

unknown

The Image Optimizer by 10web plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.0.25 via the dir parameter in the get_subdirs AJAX function. This allows authenticated attackers with subscriber-level permissions or above to view the directory structure of arbitrary folders on t...

Affected:
up to 1.0.26
Fixed in:
1.0.26
Disclosed:
Apr 19, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database