CVE-2023-2117: 10web Image Optimizer
Low severity, CVSS 2.7. EPSS: 0.7% chance of exploitation in the next 30 days.
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.
Affected products
- 10web Image Optimizer: before 1.0.27 (fixed in 1.0.27)
Published 2023-05-30. Last modified 2026-06-17.