CVE-2020-36750: EWWW Image Optimizer <= 5.8.1 - Cross-Site Request Forgery Bypass
The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewwwnggbulkinit() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-36750?
CVE-2020-36750 refers to a Cross-Site Request Forgery vulnerability in the EWWW Image Optimizer plugin for WordPress.
What is the severity of CVE-2020-36750?
The severity of CVE-2020-36750 is medium with a severity value of 4.3.
How does CVE-2020-36750 affect EWWW Image Optimizer plugin for WordPress?
CVE-2020-36750 affects EWWW Image Optimizer plugin for WordPress by allowing unauthenticated attackers to perform bulk image optimization.
How can I fix CVE-2020-36750?
To fix CVE-2020-36750, update the EWWW Image Optimizer plugin for WordPress to version 5.8.2 or above.
Where can I find more information about CVE-2020-36750?
You can find more information about CVE-2020-36750 on the following links: [Link 1](https://blog.nintechnet.com/25-wordpress-plugins-vulnerable-to-csrf-attacks/), [Link 2](https://blog.nintechnet.com/more-wordpress-plugins-and-themes-vulnerable-to-csrf-attacks/), [Link 3](https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-1/).