Impact
The vulnerability is a broken access control flaw that allows individuals who should be unable to view certain subscriber content to gain access. This weakness is represented by CWE-862. An attacker could read or download protected media files or user data that the plugin is intended to hide from non‑authorized visitors. The impact is limited to confidentiality loss; integrity and availability are not directly affected unless the attacker forces additional actions using the accessed content.
Affected Systems
Any WordPress site running the Optimole image optimization plugin version 4.2.14 or earlier is affected. The vulnerability exists within the plugin’s access validation layer and can affect all embedded endpoints that serve image data to subscribers. Sites using earlier versions without the latest security build must be upgraded.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity risk. EPSS is not available, so the likelihood of exploitation is unclear but not considered negligible. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation reports. Attackers would need to identify a target site using the vulnerable plugin, and the flaw appears to be exploitable remotely via web requests that bypass the subscriber check. No special privileges or credentials appear required beyond what an attacker can obtain through normal web interactions.
OpenCVE Enrichment