Eklenti güvenlik geçmişi
Robin Image Optimizer güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Robin Image Optimizer – Unlimited Image Optimization, WebP & AVIF eklentisi için 4 açık kaydı bulunuyor; en yenisi 30 Eylül 2026 tarihli. Bunların 1 tanesi kritik veya yüksek önemde, 1 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 2.0.9.
- Toplam kayıt
- 4
- Kritik veya yüksek
- 1
- Oturumsuz istismar
- 1
- Son kayıt
- 30 Eylül 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.0.8 öncesi · Oturum açmadan istismar edilebilir
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.
Türkçe kayıt ve ne yapmalıeksik yetki denetimi
Etkilenen sürümler: 2.0.8 öncesi
The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer WordPress plugin before 2.0.8 pages and disclose the Robin Image Optimizer WordPress plugin before 2.0.8's stored settings.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.0.2 ve öncesi
The Robin Image Optimizer – Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of a Media Library image in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
eksik yetki denetimi
Etkilenen sürümler: 1.6.9 ve öncesi
Missing Authorization vulnerability in Creative Motion Robin image optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robin image optimizer: from n/a through 1.6.9.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 8 Ekim 2026 itibarıyla.