ImageRecycle pdf & image compression <= 3.1.14 - Missing Authorization in Several AJAX Actions
Description
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform unauthorized actions, such as updating plugin settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized settings modification due to missing capability checks on AJAX actions, affecting versions up to 3.1.14.
Vulnerability
The ImageRecycle pdf & image compression plugin for WordPress (versions up to and including 3.1.14) fails to perform capability checks on several AJAX actions. This allows authenticated users with Subscriber-level access or higher to perform unauthorized modifications, such as updating plugin settings. The missing capability check means that any authenticated user can trigger these AJAX endpoints without proper authorization. [1]
Exploitation
An attacker needs only a valid WordPress account with Subscriber-level access or above. No additional privileges are required. The attacker can send crafted AJAX requests to the vulnerable endpoints, which are accessible to authenticated users. The exact sequence involves identifying the AJAX actions that lack capability checks and then sending requests with the desired parameters to modify plugin settings.
Impact
Successful exploitation allows an attacker to modify plugin settings arbitrarily. This could lead to misconfiguration of the image compression service, potential data exposure, or disruption of service. The attacker gains the ability to change settings that should only be accessible to administrators, thereby compromising the integrity of the plugin's configuration.
Mitigation
The vulnerability is fixed in version 3.1.15 and later. Users should update to the latest version (3.1.18 as of the reference date) immediately. No workarounds are available for unpatched versions. The plugin is actively maintained, and updating is the recommended mitigation. [1]
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3<=3.1.14+ 1 more
- (no CPE)range: <=3.1.14
- (no CPE)range: 0
Patches
1Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.