---
id: CVE-2026-90953
title: >-
  The Image Optimizer  WordPress plugin before 1.7.7 does not enforce its
  intended capability check on several of its read REST routes, allowing any
  authenticated user to read attachment metadata and site-wide statistics that
  should be res…
summary: >-
  The Image Optimizer  WordPress plugin before 1.7.7 does not enforce its
  intended capability check on several of its read REST routes, allowing any
  authenticated user to read attachment metadata and site-wide statistics that
  should be res…
severity: none
cwe:
  - CWE-200
product: Image Optimizer
affected:
  - image_optimizer < 1.7.7
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T06:17:08.883'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90953'
references:
  - url: 'https://wpscan.com/vulnerability/38412622-513f-41ea-9968-192f357d360e/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T06:58:55.556Z'
---

## Overview

The Image Optimizer  WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be restricted to administrators.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
