ThreatPress

WordPress Vulnerabilities Database

Back

WordPress Smush Image Compression and Optimization plugin <= 2.9.1 - Authenticated XSS & Phar Deserialization vulnerabilities

Product
Smush Image Compression and Optimization
Description
Authenticated XSS & Phar Deserialization vulnerabilities found by RIPS Technologies in WordPress Smush Image Compression and Optimization plugin (versions <= 2.9.1).
Solution
Update the WordPress Smush Image Compression and Optimization plugin to the latest available version (at least 3.0.0).
Classification
Type Multi
References
Plugin changelog
CVE
Name CVE-N/A
Versions
Affected In <= 2.9.1
Fixed In 3.0.0
Disclosure date
2018-12-10
Credits
RIPS Technologies
Submitter
ThreatPress