CVE-2024-1089
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 29, 2024
Summary
CVE-2024-1089 is a vulnerability affecting the ImageRecycle plugin for WordPress. The issue lies in the lack of capability checks on the optimizeAllOn function, present in all versions up to 3.1.13. This flaw allows authenticated attackers, with subscriber-level access and above, to manipulate image optimization settings, leading to unauthorized data modification. This vulnerability poses a significant risk to WordPress sites using the ImageRecycle plugin and requires immediate attention for patching or mitigation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share