CVE-2024-1934: WP Compress – Image Optimizer <= 6.11.08 - Missing Authorization to Unauthenticated CDN Modification
The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpslocalcompress::construct' function in all versions up to, and including, 6.11.10. This makes it possible for unauthenticated attackers to reset the CDN region and set a malicious URL to deliver images.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1934?
The severity of CVE-2024-1934 is considered high due to the potential for unauthorized data modification by unauthenticated attackers.
How do I fix CVE-2024-1934?
To fix CVE-2024-1934, update the WP Compress – Image Optimizer plugin to version 6.11.11 or later to implement the necessary capability checks.
Who is affected by CVE-2024-1934?
Users of the WP Compress – Image Optimizer plugin for WordPress versions up to and including 6.11.10 are affected by CVE-2024-1934.
What type of vulnerability is CVE-2024-1934?
CVE-2024-1934 is an unauthorized modification of data vulnerability due to a missing capability check.
Can CVE-2024-1934 be exploited remotely?
Yes, attackers can exploit CVE-2024-1934 remotely without authentication to modify data.