What the vulnerability does
01Description
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.
Explanation of Vulnerability in Simple Terms
ShortPixel Adaptive Images for WordPress contains an access control flaw that allows authenticated users with low privileges to modify settings they should not have access to. The vulnerability affects versions up to 3.3.1. An attacker with a low-privilege account (such as a subscriber or contributor) can alter plugin configuration without proper authorization checks.
What an attacker can do
Modify ShortPixel plugin settings that should be restricted to administrators.
Potential impact on your site
Unauthorized users can change image optimization settings, potentially disrupting site functionality or exposing configuration details.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (subscriber, contributor, or similar).
Key dates
External resources
Related vulnerabilities