CVE-2024-4445

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit plugin settings, including storing cross-site scripting, in multisite environments.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpcompress:wp_compress:*:*:*:*:*:wordpress:*:*

History

11 Aug 2025, 14:42

Type Values Removed Values Added
CWE CWE-601
First Time Wpcompress wp Compress
Wpcompress
CPE cpe:2.3:a:wpcompress:wp_compress:*:*:*:*:*:wordpress:*:*
References () https://plugins.trac.wordpress.org/browser/wp-compress-image-optimizer/trunk/classes/mu.class.php?rev=2946135 - () https://plugins.trac.wordpress.org/browser/wp-compress-image-optimizer/trunk/classes/mu.class.php?rev=2946135 - Product
References () https://plugins.trac.wordpress.org/changeset/3082085/#file655 - () https://plugins.trac.wordpress.org/changeset/3082085/#file655 - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/830f53a4-da3b-4a95-99f1-c4a4c8e6944c?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/830f53a4-da3b-4a95-99f1-c4a4c8e6944c?source=cve - Third Party Advisory

21 Nov 2024, 09:42

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/browser/wp-compress-image-optimizer/trunk/classes/mu.class.php?rev=2946135 - () https://plugins.trac.wordpress.org/browser/wp-compress-image-optimizer/trunk/classes/mu.class.php?rev=2946135 -
References () https://plugins.trac.wordpress.org/changeset/3082085/#file655 - () https://plugins.trac.wordpress.org/changeset/3082085/#file655 -
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/830f53a4-da3b-4a95-99f1-c4a4c8e6944c?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/830f53a4-da3b-4a95-99f1-c4a4c8e6944c?source=cve -
Summary
  • (es) El complemento WP Compress – Image Optimizer [All-In-One] para WordPress es vulnerable a modificaciones no autorizadas de datos debido a una falta de verificación de capacidad en varias funciones en versiones hasta la 6.20.01 incluida. Esto hace posible que atacantes autenticados, con permisos de nivel de suscriptor y superiores, editen la configuración de los complementos, incluido el almacenamiento de Cross Site Scripting, en entornos multisitio.

14 May 2024, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 16:17

Updated : 2025-08-11 14:42


NVD link : CVE-2024-4445

Mitre link : CVE-2024-4445

CVE.ORG link : CVE-2024-4445


JSON object : View

Products Affected

wpcompress

  • wp_compress
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')