CVE-2023-40600

Source
https://cve.org/CVERecord?id=CVE-2023-40600
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-40600.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-40600
Published
2023-11-30T15:00:09.354Z
Modified
2026-07-15T01:48:57.862939641Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
WordPress EWWW Image Optimizer Plugin <= 7.2.0 is vulnerable to Sensitive Data Exposure
Details

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a through 7.2.0.

Database specific
{
    "cna_assigner": "Patchstack",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "7.2.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "7.2.0"
                }
            ],
            "source": "DESCRIPTION"
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/40xxx/CVE-2023-40600.json",
    "cwe_ids": [
        "CWE-200"
    ]
}
References

Affected packages

Git / github.com/nosilver4u/ewww-image-optimizer

Affected ranges

Type
GIT
Repo
https://github.com/nosilver4u/ewww-image-optimizer
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:ewww:image_optimizer:*:*:*:*:*:wordpress:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.2.1"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v3.*
v3.3.0
v3.3.1
v3.4.1
v3.5.0
v4.*
v4.0.0
v4.0.3
v4.0.6
v4.2.2
v4.3.1
v4.3.2
v4.4.0
v4.4.1
v4.4.2
v4.5.0
v4.5.1
v4.5.2
v4.5.3
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.8.0
v4.8.1
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v5.*
v5.0.0
v5.1.0
v5.1.2
v5.1.3
v5.2.0
v5.2.2
v5.2.3
v5.2.4
v5.3.1
v5.3.2
v5.4.0
v5.4.1
v5.6.0
v5.6.1
v5.7.0
v5.8.0
v5.8.2
v6.*
v6.0.0
v6.0.1
v6.0.2
v6.1.0
v6.1.1
v6.1.2
v6.1.3
v6.1.4
v6.1.5
v6.1.6
v6.1.7
v6.1.8
v6.1.9
v6.2.0
v6.2.1
v6.2.2
v6.2.3
v6.2.4
v6.2.5
v6.4.0
v6.4.1
v6.4.2
v6.5.0
v6.5.1
v6.5.2
v6.6.0
v6.7.0
v6.8.0
v6.9.0
v6.9.1
v6.9.2
v6.9.3
v7.*
v7.0.0
v7.0.1
v7.0.2
v7.1.0
v7.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-40600.json"