CVE Database /
CVE-2017-15079
CVE · High
CVE-2017-15079 — Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 2.7.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2017-15079
|
Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 2.7.6 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
High
7.5
|
< 2.7.6
|
2.7.6 |
2017-09-21 |
—
|
CVE-2017-15079
The Smush image optimization plugin for WordPress contained a file traversal vulnerability that allowed unauthorized access to files outside the intended directory structure. This flaw affected versions prior to 2.7.6, where improper path validation could be exploited to read arbitrary files on the server. The vulnerability has been resolved in version 2.7.6 and later releases.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings