CVE-2024-6631 - ImageRecycle WordPress Plugin JSON Hijacking & Unauthorized Data Modification
<strong>CVE ID : </strong>CVE-2024-6631
<br>
<strong>Published : </strong> Aug. 24, 2024, 3:15 a.m. | 1 hour, 36 minutes ago
<br>
<strong>Description : </strong>The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform unauthorized actions, such as updating plugin settings.
<br>
<strong>Severity:</strong> 5.0 | MEDIUM
<br>
Visit the link for more details, such as CVSS details, affected products, timeline, and more...