Unrated severityNVD Advisory· Published Sep 30, 2026
CVE-2026-90953
CVE-2026-90953
Description
The Image Optimizer WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be restricted to administrators.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.7.7
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.