The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF checks for any of its AJAX actions, allowing an attackers to trick logged in users to perform various actions on their behalf on the site.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2022-11-14T00:00:00

Updated: 2024-08-03T00:39:07.578Z

Reserved: 2022-07-17T00:00:00

Link: CVE-2022-2449

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-11-14T15:15:19.013

Modified: 2022-11-16T19:00:07.810

Link: CVE-2022-2449

cve-icon Redhat

No data.