CVE-2023-3352: Smush – Lazy Load Images, Optimize & Compress Images <= 3.16.4 - Missing Authorization to Resmush List Deletion
The Smush plugin for WordPress is vulnerable to unauthorized deletion of the resmush list due to a missing capability check on the deleteresmushlist() function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to delete the resmush list for Nextgen or the Media Library.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3352?
CVE-2023-3352 is considered a high severity vulnerability due to the potential for authenticated attackers to delete critical resmush lists.
How do I fix CVE-2023-3352?
To fix CVE-2023-3352, update the Smush plugin to version 3.16.5 or later.
Who is affected by CVE-2023-3352?
CVE-2023-3352 affects users of the Smush plugin for WordPress versions up to and including 3.16.4.
What does CVE-2023-3352 target in the Smush plugin?
CVE-2023-3352 targets the delete_resmush_list() function, which lacks proper capability checks.
Can low-level users exploit CVE-2023-3352?
Yes, authenticated users with minimal permissions, such as subscribers, can exploit CVE-2023-3352 to delete the resmush list.