ShortPixel Adaptive Images <= 3.3.1 - Subscriber+ Arbitrary Settings Update

2022-04-25 10:45
Tien Nguyen Ahn

Vulnerability Overview

Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.

Technical Analysis

REMEDIATION: Update to version 3.4.0, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C