7.5
CVSSv3

CVE-2023-40600

Published: 30/11/2023 Updated: 06/12/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a up to and including 7.2.0.

Vulnerable Product Search on Vulmon Subscribe to Product

ewww image optimizer

Github Repositories

EWWW Image Optimizer <= 7.2.0 - Unauthenticated Sensitive Information Exposure via Debug Log

CVE-2023-40600 EWWW Image Optimizer &lt;= 720 - Unauthenticated Sensitive Information Exposure via Debug Log Description The EWWW Image Optimizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 720 via the debug_log function This makes it possible for unauthenticated attackers to extract sensitive debug data wh