CVE-2024-1339

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

4.3medium3.x
0246810

CVSS Score: 4.3/10

All CVSS Scores

CVSS 3.x
4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the reinitialize function. This makes it possible for unauthenticated attackers to remove all plugin data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

anchore_overridesnvd

CWEs

CWE-352

Vulnerable Software (2)

Type: Configuration

Operating System:

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:imagerecycle:imagerecycle_pdf_\\\u0026_image_compression:*:*:*:*:*:wordpress:*:*",          "versionEndExcludin...

Source: anchore_overrides

Type: Configuration

Vendor: imagerecycle

Product: imagerecycle_pdf_&_image_compression

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:imagerecycle:imagerecycle_pdf_\\\u0026_image_compression:*:*:*:*:*:wordpress:*:*",      "versionEndExcluding": "3.1.14",      "vulnerable": true...

Source: nvd