NA

CVE-2023-6699

Published: 11/01/2024 Updated: 17/01/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated malicious users to read the contents of arbitrary files on the server, which can contain sensitive information.

Vulnerable Product Search on Vulmon Subscribe to Product

wpcompress wp compress