{"id":"CVE-2026-90953","title":"The Image Optimizer  WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be res…","summary":"The Image Optimizer  WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be res…","severity":"none","cwe":["CWE-200"],"product":"Image Optimizer","affected":["image_optimizer < 1.7.7"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T06:17:08.883","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90953","references":[{"url":"https://wpscan.com/vulnerability/38412622-513f-41ea-9968-192f357d360e/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T06:58:55.556Z","slug":"CVE-2026-90953","body":"## Overview\n\nThe Image Optimizer  WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be restricted to administrators.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}