CVE-2023-0619: Kraken.io Image Optimizer <= 2.6.8 - Missing Authorization to Authenticated (Subscriber+) Plugin Options Update
The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset image optimizations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0619?
CVE-2023-0619 is considered a high severity vulnerability as it allows authenticated attackers to perform actions they shouldn't be authorized to do.
How do I fix CVE-2023-0619?
To fix CVE-2023-0619, update the Kraken.io Image Optimizer plugin to the latest version that is above 2.6.8 where the vulnerability is patched.
What systems are affected by CVE-2023-0619?
CVE-2023-0619 affects the Kraken.io Image Optimizer plugin for WordPress in versions up to and including 2.6.8.
Who can exploit CVE-2023-0619?
CVE-2023-0619 can be exploited by authenticated users with subscriber-level permissions or higher.
What kind of attack can result from CVE-2023-0619?
CVE-2023-0619 can lead to unauthorized actions such as image optimization resets by exploiting the authorization bypass.