What the vulnerability does
01Description
Missing Authorization vulnerability in Acme Themes Acme Fix Images acme-fix-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Acme Fix Images: from n/a through <= 1.0.0.
Explanation of Vulnerability in Simple Terms
02Summary
Acme Fix Images version 1.0.0 and earlier lacks proper authorization checks, allowing authenticated users to modify image data they should not have access to. An attacker with a low-privilege account can alter images across the site without restriction. The vulnerability affects integrity but not confidentiality or availability. Update to a version newer than 1.0.0 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Modify or alter images on the site without proper permission checks.
Potential impact on your site
04Site Impact
Authenticated users can tamper with images they should not be able to edit, risking site content integrity.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site.
Key dates
06Disclosure timeline
December 9, 2024
CVE published
April 29, 2026
Record updated