First published: Mon Apr 25 2022(Updated: )
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
ShortPixel Adaptive Images | <=3.3.1 |
Update to 3.4.0 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-29417.
The affected software is ShortPixel's ShortPixel Adaptive Images plugin version <= 3.3.1 at WordPress.
The severity of the vulnerability is medium with a CVSS score of 4.3.
An attacker with a low user role like a subscriber or higher can exploit the vulnerability to change the plugin settings.
Yes, patches and fixes are available. You can find them at the following references: [Patchstack](https://patchstack.com/database/vulnerability/shortpixel-adaptive-images/wordpress-shortpixel-adaptive-images-plugin-3-3-1-subscriber-plugin-settings-update-vulnerability) and [WordPress Plugin Directory](https://wordpress.org/plugins/shortpixel-adaptive-images/#developers).