Nosilver4U Ewww Image Optimizer vulnerabilities
2 known vulnerabilities affecting nosilver4u/ewww_image_optimizer.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2020-36750P4MEDIUMCVSS 4.3≤ 5.8.12023-07-12
CVE-2020-36750 [MEDIUM] CWE-352 CVE-2020-36750: The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in version
The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a forged request granted they can tri
nvd
CVE-2024-31924P4MEDIUMCVSS 4.3≤ 7.2.32024-04-10
CVE-2024-31924 [MEDIUM] CWE-352 CVE-2024-31924: Cross-Site Request Forgery (CSRF) vulnerability in nosilver4u EWWW Image Optimizer ewww-image-optimi
Cross-Site Request Forgery (CSRF) vulnerability in nosilver4u EWWW Image Optimizer ewww-image-optimizer.This issue affects EWWW Image Optimizer: from n/a through <= 7.2.3.
nvd