CVE · Medium

CVE-2023-40600 — EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-40600 EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 7.2.1 7.2.1 2023-11-14

CVE-2023-40600

The EWWW Image Optimizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.0 via the debug_log function. This makes it possible for unauthenticated attackers to extract sensitive debug data when debug logging is enabled.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.