CVE-2026-89190
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 30, 2026
Vendor
unknown
Description
The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer WordPress plugin before 2.0.8 pages and disclose the Robin Image Optimizer WordPress plugin before 2.0.8's stored settings.