CVE-2023-2117: Image Optimizer by 10web < 1.0.27 - Admin+ Path Traversal
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the getsubdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-2117.
What is the title of this vulnerability?
The title of this vulnerability is 'The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when…'.
What does this vulnerability affect?
This vulnerability affects the Image Optimizer by 10web WordPress plugin version 1.0.26 or below.
What is the severity of this vulnerability?
The severity of this vulnerability is low, with a severity value of 2.7.
How can the vulnerability be exploited?
The vulnerability can be exploited by high privileged users, such as admins, to inspect names of files and directories outside of the site's root.