Impact
The vulnerability is a missing authorization flaw in Zara 4 Image Compression that allows an attacker to exploit incorrectly configured access control levels. This weakness enables an unauthorized user to interact with plugin functionality that should be restricted, potentially manipulating image compression settings. The impact is limited to the plugin’s scope but could lead to unintended configuration changes or data exposure within the WordPress site.
Affected Systems
Zara 4 Image Compression for WordPress, versions up through 1.2.17.2 are affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1% suggests low current exploitation probability. The vulnerability is not cataloged in CISA KEV. The likely attack vector is remote via the web interface, where a non-privileged or unprivileged user could access the plugin’s administrative endpoints. Exploitation requires no advanced techniques but hinges on the absence of proper role checks before executing plugin actions.
OpenCVE Enrichment
EUVD