Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High2
Medium1
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2026-07-02

CVE-2026-5821 - Image Optimizer Plugin

The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file deletion operations without verifying they are within the uploads directory. The plugin stores backup file paths in the image_optimizer_metadata post meta field and trusts these paths completely when deleting backups on the delete_attachment hook. An authenticated attacker with Author-level access can edit the image_optimizer_metadata post meta on…

PLUGIN Image Optimizer

CVE-2026-5821

HIGH CVSS 8.1 2026-07-02
Threat Entry Updated 2025-08-09

CVE-2024-1934 - Image Optimizer Plugin

The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wps_local_compress::__construct' function in all versions up to, and including, 6.11.10. This makes it possible for unauthenticated attackers to reset the CDN region and set a malicious URL to deliver images.

PLUGIN Image Optimizer

CVE-2024-1934

HIGH CVSS 7.5 2024-04-09
Threat Entry Updated 2024-11-21

CVE-2023-2122 - Image Optimizer Plugin

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.

PLUGIN Image Optimizer

CVE-2023-2122

MEDIUM CVSS 6.1 2023-08-16
Threat Entry Updated 2025-01-10

CVE-2023-2117 - Image Optimizer Plugin

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

PLUGIN Image Optimizer

CVE-2023-2117

LOW CVSS 2.7 2023-05-30
Scroll to top