Vulnerability Description
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce validation on several functions in the class/class-image-otimizer.php file. This makes it possible for unauthenticated attackers to update plugin settings along with performing other actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Imagerecycle | Imagerecycle Pdf \& Image Compression | < 3.1.15 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/3119956/imagerecycle-pdf-image-compPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a06bba7f-0259-4b87-b3fThird Party Advisory
FAQ
What is CVE-2024-8120?
CVE-2024-8120 is a vulnerability with a CVSS score of 4.7 (MEDIUM). The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce valida...
How severe is CVE-2024-8120?
CVE-2024-8120 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-8120?
Check the references section above for vendor advisories and patch information. Affected products include: Imagerecycle Imagerecycle Pdf \& Image Compression.