THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2023-3352

Smush – Lazy Load Images, Optimize & Compress Images <= 3.16.4 - Missing Authorization to Resmush List Deletion

Assigner:Wordfence
Reserved:2023-06-21
Published:2024-06-21
Updated:2024-06-21

Description

The Smush plugin for WordPress is vulnerable to unauthorized deletion of the resmush list due to a missing capability check on the delete_resmush_list() function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to delete the resmush list for Nextgen or the Media Library.



MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

*
affected

Timeline

2024-06-20:Disclosed

Credits

Truoc Phan finder

An Đặng finder

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/dfbaa3e4-40c2-41d8-996c-232e27a04b73?source=cve

https://plugins.trac.wordpress.org/changeset/3105107/wp-smushit/trunk/app/class-ajax.php

cve.org CVE-2023-3352

nvd.nist.gov CVE-2023-3352

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-3352