ShortPixel Adaptive Images <= 3.3.1 - Subscriber+ Arbitrary Settings Update
2022-04-25 10:45
Tien Nguyen AhnStrategic Overview
StatusPatched in 3.4.0
Affected Version
<= 3.3.1CVSS4.3Medium
CVE
CVE-2022-29417Vulnerability Overview
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.
Technical Analysis
REMEDIATION: Update to version 3.4.0, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C