Input validation vulnerability in Image Optimizer by 10web – Image Optimizer and Compression plugin 1.0.26

The Image Optimizer WD plugin for WordPress is vulnerable to a security issue known as “Stored Cross-Site Scripting”. This means that if the plugin is installed on a WordPress website, and the website has specific settings enabled, it could be possible for malicious actors with administrator-level permissions to inject web scripts into pages on the website. These scripts would then be executed by any user who views the injected page. This security issue only affects websites that have either a multi-site installation or have disabled a specific setting called “unfiltered_html”.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.