Input validation vulnerability in Image Compressor & Optimizer – iLoveIMG 1.0.6

The Image Compressor & Optimizer – iLoveIMG plugin for WordPress has a security vulnerability that could make it possible for people with administrative access to inject a malicious piece of code into the plugin. This code could be used to delete files, access sensitive information, or even execute code. All versions of the plugin up to 1.0.6 are vulnerable. There is no additional protection from the plugin itself, so if there is a different plugin or theme installed on the website, the malicious code could be even more dangerous.

Detected in:

Image Compressor & Optimizer – iLoveIMG fixed vulnerable versions: >= * < 1.0.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.