Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Kraken\.io_image_optimizer
(Kraken)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 2 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-09-23 | CVE-2022-38454 | Cross-Site Request Forgery (CSRF) vulnerability in Kraken.io Image Optimizer plugin <= 2.6.5 at WordPress. | Kraken\.io_image_optimizer | 8.8 | ||
2023-02-01 | CVE-2023-0619 | The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset image optimizations. | Kraken\.io_image_optimizer | 6.5 |