VYPR
Unrated severityNVD Advisory· Published Aug 24, 2024· Updated Apr 8, 2026

ImageRecycle pdf & image compression <= 3.1.14 - Missing Authorization in Several AJAX Actions

CVE-2024-6631

Description

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform unauthorized actions, such as updating plugin settings.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized settings modification due to missing capability checks on AJAX actions, affecting versions up to 3.1.14.

Vulnerability

The ImageRecycle pdf & image compression plugin for WordPress (versions up to and including 3.1.14) fails to perform capability checks on several AJAX actions. This allows authenticated users with Subscriber-level access or higher to perform unauthorized modifications, such as updating plugin settings. The missing capability check means that any authenticated user can trigger these AJAX endpoints without proper authorization. [1]

Exploitation

An attacker needs only a valid WordPress account with Subscriber-level access or above. No additional privileges are required. The attacker can send crafted AJAX requests to the vulnerable endpoints, which are accessible to authenticated users. The exact sequence involves identifying the AJAX actions that lack capability checks and then sending requests with the desired parameters to modify plugin settings.

Impact

Successful exploitation allows an attacker to modify plugin settings arbitrarily. This could lead to misconfiguration of the image compression service, potential data exposure, or disruption of service. The attacker gains the ability to change settings that should only be accessible to administrators, thereby compromising the integrity of the plugin's configuration.

Mitigation

The vulnerability is fixed in version 3.1.15 and later. Users should update to the latest version (3.1.18 as of the reference date) immediately. No workarounds are available for unpatched versions. The plugin is actively maintained, and updating is the recommended mitigation. [1]

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

1

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.