WPHizmet

Eklenti güvenlik geçmişi

Robin Image Optimizer güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Robin Image Optimizer – Unlimited Image Optimization, WebP & AVIF eklentisi için 4 açık kaydı bulunuyor; en yenisi 30 Eylül 2026 tarihli. Bunların 1 tanesi kritik veya yüksek önemde, 1 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 2.0.9.

Toplam kayıt
4
Kritik veya yüksek
1
Oturumsuz istismar
1
Son kayıt
30 Eylül 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-89193Yüksek · 7,530 Eylül 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 2.0.8 öncesi · Oturum açmadan istismar edilebilir

    The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-89190Orta · 4,330 Eylül 2026

    eksik yetki denetimi

    Etkilenen sürümler: 2.0.8 öncesi

    The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer WordPress plugin before 2.0.8 pages and disclose the Robin Image Optimizer WordPress plugin before 2.0.8's stored settings.

  • CVE-2026-1319Orta · 6,45 Şubat 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 2.0.2 ve öncesi

    The Robin Image Optimizer – Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of a Media Library image in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2024-43122Orta · 6,51 Kasım 2024

    eksik yetki denetimi

    Etkilenen sürümler: 1.6.9 ve öncesi

    Missing Authorization vulnerability in Creative Motion Robin image optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robin image optimizer: from n/a through 1.6.9.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 8 Ekim 2026 itibarıyla.