GHSA-q3p9-mmwf-qgrcMediumCVSS 6.5
The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing...
🔗 CVE IDs covered (1)
📋 Description
The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials.