CVE-2024-9361

The Bulk images optimizer: Resize, optimize, convert to webp, rename … plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_configuration' function in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin options.
Configurations

Configuration 1 (hide)

cpe:2.3:a:giuliopanda:bulk_images_optimizer:*:*:*:*:*:wordpress:*:*

History

01 Nov 2024, 18:46

Type Values Removed Values Added
First Time Giuliopanda
Giuliopanda bulk Images Optimizer
CPE cpe:2.3:a:giuliopanda:bulk_images_optimizer:*:*:*:*:*:wordpress:*:*
Summary
  • (es) El complemento Bulk images optimizer: Resize, optimize, convert to webp, rename … para WordPress es vulnerable a la modificación no autorizada de datos debido a una falta de comprobación de capacidad en la función 'save_configuration' en todas las versiones hasta la 2.0.1 incluida. Esto permite que atacantes autenticados, con acceso de nivel de suscriptor y superior, actualicen las opciones del complemento.
References () https://plugins.trac.wordpress.org/browser/bulk-image-resizer/trunk/includes/class-bir-loader.php#L44 - () https://plugins.trac.wordpress.org/browser/bulk-image-resizer/trunk/includes/class-bir-loader.php#L44 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/a189e436-e8af-4379-aa6e-2d1a4a2d4bfa?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/a189e436-e8af-4379-aa6e-2d1a4a2d4bfa?source=cve - Third Party Advisory

18 Oct 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-18 05:15

Updated : 2024-11-01 18:46


NVD link : CVE-2024-9361

Mitre link : CVE-2024-9361

CVE.ORG link : CVE-2024-9361


JSON object : View

Products Affected

giuliopanda

  • bulk_images_optimizer
CWE
CWE-862

Missing Authorization