CVE-2024-1934

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/04/2024
Last modified:
09/08/2025

Description

The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wps_local_compress::__construct' function in all versions up to, and including, 6.11.10. This makes it possible for unauthenticated attackers to reset the CDN region and set a malicious URL to deliver images.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wpcompress:wp_compress:*:*:*:*:*:wordpress:*:* 6.11.11 (excluding)