CVE-2024-4445: WP Compress – Image Optimizer [All-In-One] <= 6.20.01 - Missing Authorization
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit plugin settings, including storing cross-site scripting, in multisite environments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/wp-compress-image-optimizer-all-in-oneto a version that resolves this vulnerability.Fixed in 6.20.01
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4445?
CVE-2024-4445 is a high severity vulnerability allowing unauthorized data modification.
How do I fix CVE-2024-4445?
To fix CVE-2024-4445, update the WP Compress – Image Optimizer plugin to version 6.20.02 or later.
Who is affected by CVE-2024-4445?
CVE-2024-4445 affects users of the WP Compress – Image Optimizer plugin for WordPress up to version 6.20.01.
What type of vulnerability is CVE-2024-4445?
CVE-2024-4445 is categorized as a data modification vulnerability due to insufficient capability checks.
Can CVE-2024-4445 be exploited remotely?
Yes, CVE-2024-4445 can be exploited by authenticated attackers with subscriber-level access.