The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/1b3ff124-f973-4584-a7d7-26cc404bfe2b | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/1b3ff124-f973-4584-a7d7-26cc404bfe2b | Exploit Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 07:01
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2022-11-14 15:15
Updated : 2025-04-30 20:15
NVD link : CVE-2022-2450
Mitre link : CVE-2022-2450
CVE.ORG link : CVE-2022-2450
JSON object : View
Products Affected
                resmush.it
- resmush.it_image_optimizer
CWE
                
                    
                        
                        CWE-862
                        
            Missing Authorization
