CVE-2026-89190
Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajax
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer WordPress plugin before 2.0.8 pages and disclose the Robin Image Optimizer WordPress plugin before 2.0.8's stored settings.
| Vendor | unknown |
| Product | robin image optimizer |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown robin image optimizer
Be the first to know when new unknown vulnerabilities affecting unknown robin image optimizer are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Robin Image Optimizer
0 < 2.0.8
References
Credits
Abdullah Kareem WPScan