plugin

Imagerecycle Pdf Image Compression Vulnerabilities

31 known security issues reported for the Imagerecycle Pdf Image Compression WordPress plugin. Most recent disclosed Dec 13, 2024.

15 medium

Running Imagerecycle Pdf Image Compression on your site? Check whether your installed version is affected.

Scan your site free

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.17

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression allows Reflected XSS.This issue affects ImageRecycle pdf & image compression: from n/a through 3.1.16.

Affected:
up to 3.1.17
Fixed in:
3.1.17
Disclosed:
Dec 13, 2024

CVE-2024-54266 on NVD →

ImageRecycle pdf & image compression <= 3.1.16 - Reflected Cross-Site Scripting

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 3.1.16
Fixed in:
3.1.17
Disclosed:
Dec 10, 2024

CVE-2024-54266 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.15

unknown

[en] The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to per...

Affected:
up to 3.1.15
Fixed in:
3.1.15
Disclosed:
Aug 24, 2024

CVE-2024-6631 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.15

unknown

[en] The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce validation on several functions in the class/class-image-otimizer.php file. This makes it possible for unauthenticated at...

Affected:
up to 3.1.15
Fixed in:
3.1.15
Disclosed:
Aug 24, 2024

CVE-2024-8120 on NVD →

ImageRecycle pdf & image compression <= 3.1.14 - Missing Authorization in Several AJAX Actions

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform...

CVSS:
5
Affected:
up to 3.1.14
Fixed in:
3.1.15
Disclosed:
Aug 23, 2024

CVE-2024-6631 on NVD →

ImageRecycle pdf & image compression <= 3.1.14 - Cross-Site Request in Several AJAX Actions

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce validation on several functions in the class/class-image-otimizer.php file. This makes it possible for unauthenticated attacke...

CVSS:
4.7
Affected:
up to 3.1.14
Fixed in:
3.1.15
Disclosed:
Aug 23, 2024

CVE-2024-8120 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.14

unknown

[en] The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the optimizeAllOn function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above,...

Affected:
up to 3.1.14
Fixed in:
3.1.14
Disclosed:
Feb 20, 2024

CVE-2024-1089 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.14

unknown

[en] The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stopOptimizeAll function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above...

Affected:
up to 3.1.14
Fixed in:
3.1.14
Disclosed:
Feb 20, 2024

CVE-2024-1090 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.14

unknown

[en] The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enableOptimization function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and ab...

Affected:
up to 3.1.14
Fixed in:
3.1.14
Disclosed:
Feb 20, 2024

CVE-2024-0983 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.14

unknown

[en] The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the enableOptimization function. This makes it possible for unauthenticated attackers to enable image optim...

Affected:
up to 3.1.14
Fixed in:
3.1.14
Disclosed:
Feb 20, 2024

CVE-2024-1334 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.14

unknown

[en] The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the optimizeAllOn function. This makes it possible for unauthenticated attackers to modify image optimizati...

Affected:
up to 3.1.14
Fixed in:
3.1.14
Disclosed:
Feb 20, 2024

CVE-2024-1336 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.14

unknown

[en] The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reinitialize function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, t...

Affected:
up to 3.1.14
Fixed in:
3.1.14
Disclosed:
Feb 20, 2024

CVE-2024-1091 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.14

unknown

[en] The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the reinitialize function. This makes it possible for unauthenticated attackers to remove all plugin data v...

Affected:
up to 3.1.14
Fixed in:
3.1.14
Disclosed:
Feb 20, 2024

CVE-2024-1339 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.14

unknown

[en] The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the disableOptimization function. This makes it possible for unauthenticated attackers to disable the image...

Affected:
up to 3.1.14
Fixed in:
3.1.14
Disclosed:
Feb 20, 2024

CVE-2024-1335 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.14

unknown

[en] The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the stopOptimizeAll function. This makes it possible for unauthenticated attackers to modify image optimiza...

Affected:
up to 3.1.14
Fixed in:
3.1.14
Disclosed:
Feb 20, 2024

CVE-2024-1338 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.14

unknown

[en] The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disableOptimization function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and a...

Affected:
up to 3.1.14
Fixed in:
3.1.14
Disclosed:
Feb 20, 2024

CVE-2024-0984 on NVD →

ImageRecycle pdf & image compression <= 3.1.13 - Missing Authorization to Settings Update in enableOptimization

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enableOptimization function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above,...

CVSS:
4.3
Affected:
up to 3.1.13
Fixed in:
3.1.14
Disclosed:
Feb 7, 2024

CVE-2024-0983 on NVD →

ImageRecycle pdf & image compression <= 3.1.13 - Missing Authorization to Settings Update in stopOptimizeAll

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stopOptimizeAll function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to...

CVSS:
4.3
Affected:
up to 3.1.13
Fixed in:
3.1.14
Disclosed:
Feb 7, 2024

CVE-2024-1090 on NVD →

ImageRecycle pdf & image compression <= 3.1.13 - Missing Authorization to Settings Update in disableOptimization

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disableOptimization function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above,...

CVSS:
4.3
Affected:
up to 3.1.13
Fixed in:
3.1.14
Disclosed:
Feb 7, 2024

CVE-2024-0984 on NVD →

ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Settings Update in optimizeAllOn

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the optimizeAllOn function. This makes it possible for unauthenticated attackers to modify image optimization se...

CVSS:
4.3
Affected:
up to 3.1.13
Fixed in:
3.1.14
Disclosed:
Feb 7, 2024

CVE-2024-1336 on NVD →

ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Settings Update in disableOptimization

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the disableOptimization function. This makes it possible for unauthenticated attackers to disable the image opti...

CVSS:
4.3
Affected:
up to 3.1.13
Fixed in:
3.1.14
Disclosed:
Feb 7, 2024

CVE-2024-1335 on NVD →

ImageRecycle pdf & image compression <= 3.1.13 - Missing Authorization to Settings Update in optimizeAllOn

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the optimizeAllOn function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to mo...

CVSS:
4.3
Affected:
up to 3.1.13
Fixed in:
3.1.14
Disclosed:
Feb 7, 2024

CVE-2024-1089 on NVD →

ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Settings Update in stopOptimizeAll

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the stopOptimizeAll function. This makes it possible for unauthenticated attackers to modify image optimization...

CVSS:
4.3
Affected:
up to 3.1.13
Fixed in:
3.1.14
Disclosed:
Feb 7, 2024

CVE-2024-1338 on NVD →

ImageRecycle pdf & image compression <= 3.1.13 - Missing Authorization to Plugin Data Removal in reinitialize

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reinitialize function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to rem...

CVSS:
4.3
Affected:
up to 3.1.13
Fixed in:
3.1.14
Disclosed:
Feb 7, 2024

CVE-2024-1091 on NVD →

ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Plugin Data Removal in reinitialize

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the reinitialize function. This makes it possible for unauthenticated attackers to remove all plugin data via a...

CVSS:
4.3
Affected:
up to 3.1.13
Fixed in:
3.1.14
Disclosed:
Feb 7, 2024

CVE-2024-1339 on NVD →

ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Settings Update in enableOptimization

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the enableOptimization function. This makes it possible for unauthenticated attackers to enable image optimizati...

CVSS:
4.3
Affected:
up to 3.1.13
Fixed in:
3.1.14
Disclosed:
Feb 7, 2024

CVE-2024-1334 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.12

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.11 versions.

Affected:
up to 3.1.12
Fixed in:
3.1.12
Disclosed:
Sep 4, 2023

CVE-2023-40196 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.11

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.10 versions.

Affected:
up to 3.1.11
Fixed in:
3.1.11
Disclosed:
Sep 4, 2023

CVE-2023-30494 on NVD →

ImageRecycle pdf & image compression <= 3.1.10 - Reflected Cross-Site Scripting

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 3.1.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 3.1.11
Fixed in:
3.1.11
Disclosed:
Aug 11, 2023

CVE-2023-30494 on NVD →

ImageRecycle pdf & image compression <= 3.1.11 - Reflected Cross-Site Scripting

medium

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' and 's' parameters in versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...

CVSS:
6.1
Affected:
up to 3.1.11
Fixed in:
3.1.12
Disclosed:
Aug 11, 2023

CVE-2023-40196 on NVD →

ImageRecycle pdf &amp; image compression [imagerecycle-pdf-image-compression] < 3.1.11

unknown

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 3.1.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

Affected:
up to 3.1.11
Fixed in:
3.1.11
Disclosed:
Aug 11, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database