CVE-2026-90953 Overview
CVE-2026-90953 affects the Image Optimizer WordPress plugin in versions prior to 1.7.7. The plugin fails to enforce its intended capability check on several REST API read routes. Any authenticated user, including low-privilege subscribers, can query these endpoints to retrieve attachment metadata and site-wide statistics. This data is intended for administrators only.
The flaw is a broken access control issue [CWE-284] in the plugin's REST route registration. It allows information disclosure across tenant boundaries within a WordPress site.
Critical Impact
Authenticated users of any role can enumerate attachment metadata and read site-wide statistics that should remain restricted to administrators.
Affected Products
- Image Optimizer WordPress plugin versions before 1.7.7
- WordPress installations with the plugin activated
- Multi-author or membership WordPress sites where non-admin accounts exist
Discovery Timeline
- 2026-09-30 - CVE-2026-90953 published to the National Vulnerability Database (NVD)
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-90953
Vulnerability Analysis
The Image Optimizer plugin registers several REST API routes for reading attachment metadata and site optimization statistics. These routes are intended to be reachable only by administrators. The permission_callback handlers on the affected routes do not correctly verify the caller's WordPress capability, such as manage_options or edit_others_posts.
Any user with a valid WordPress session, including a subscriber account created through open registration, can call these endpoints. The server returns attachment metadata and aggregated statistics without further authorization checks. This data may include file paths, media identifiers, optimization counts, and storage figures that support reconnaissance against the target site.
The issue does not permit writes or code execution. It is limited to information disclosure over authenticated REST requests.
Root Cause
The plugin's REST route definitions either use is_user_logged_in() as the permission check or return true unconditionally from the permission_callback. Neither pattern enforces the administrator role that the endpoints were designed for. This is a missing authorization defect rather than a validation or injection flaw.
Attack Vector
An attacker first obtains any authenticated WordPress account on the target site. On sites that allow self-registration, this step is trivial. The attacker then issues authenticated HTTP GET requests to the plugin's REST routes and parses the JSON responses. No user interaction from an administrator is required.
The vulnerability mechanism is described in the WPScan Vulnerability Report. No verified exploit code is published at this time.
Detection Methods for CVE-2026-90953
Indicators of Compromise
- Authenticated REST API requests to Image Optimizer plugin routes originating from non-administrator sessions.
- Repeated GET requests to /wp-json/ endpoints associated with the plugin from a single low-privilege account.
- Unusual enumeration patterns against attachment identifiers by subscriber or contributor accounts.
Detection Strategies
- Review WordPress access logs for /wp-json/ requests tied to the Image Optimizer plugin and correlate them with the requesting user's role.
- Enable REST API request logging and alert when non-administrator roles access administrative plugin routes.
- Audit WordPress user registrations for unexpected accounts created shortly before enumeration activity.
Monitoring Recommendations
- Forward WordPress and web server logs to a centralized analytics platform for role-aware queries.
- Track baseline REST API call volumes per user role and alert on deviations.
- Monitor for sudden spikes in JSON response sizes returned to low-privilege sessions.
How to Mitigate CVE-2026-90953
Immediate Actions Required
- Upgrade the Image Optimizer WordPress plugin to version 1.7.7 or later on all affected sites.
- Audit existing WordPress user accounts and remove or disable any that are not required.
- Disable open user registration on sites that do not need it, or restrict the default role to the minimum required.
Patch Information
The vendor addressed the missing capability check in Image Optimizer version 1.7.7. Administrators should update through the WordPress plugin manager or by deploying the packaged release. Confirm the installed version after update through the WordPress admin dashboard. Refer to the WPScan Vulnerability Report for advisory details.
Workarounds
- Deactivate the Image Optimizer plugin until the update to 1.7.7 or later is applied.
- Block non-administrator access to /wp-json/ routes associated with the plugin at the web application firewall or reverse proxy layer.
- Set default_role in WordPress general settings to a role with no dashboard access, and gate registration behind manual approval.
# Restrict plugin REST routes at the reverse proxy (NGINX example)
location ~ ^/wp-json/image-optimizer/ {
# Allow only requests from administrator IP ranges
allow 203.0.113.0/24;
deny all;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
