Loading market data...
← Back to CVE feed

CVE-2026-89190

MEDIUM CVSS 4.3 View on NVD ↗

Description

The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer WordPress plugin before 2.0.8 pages and disclose the Robin Image Optimizer WordPress plugin before 2.0.8's stored settings.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Published: Sep 30, 2026 06:17 UTC Modified: Sep 30, 2026 16:28 UTC