{"error":0,"message":null,"data":{"name":"WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance","plugin":"wp-optimize","link":"https:\/\/wordpress.org\/plugins\/wp-optimize\/","latest":"1786619880","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"a7e30dbe1f41f6ff72926cfec0358943ef529848e65194a5d845e87c5a25f091","name":"WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 3.2.12","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.12","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"26830aedbc88ad9227f2593255d49db672b6b093","name":"WP-Optimize <= 3.2.11 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-optimize\/wp-optimize-3211-cross-site-request-forgery","description":"The WP-Optimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.11. This is due to missing or incorrect nonce validation on the 'is_valid_request' function. This makes it possible for unauthenticated attackers to manage and modify cache and minification settings and dismiss notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-02-06"}],"impact":[]},{"uuid":"062373c659861716447dc56c256206865faa9cb0f1360308b28a563542b3746e","name":"WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 3.2.12","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.12","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"52979f0f09694daed9c6f207328b1c26f3751668","name":"WordPress  WP-Optimize Plugin  <= 3.2.11 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-optimize\/vulnerability\/wordpress-wp-optimize-plugin-3-2-11-cross-site-request-forgery-vulnerability","description":"Update the WordPress WP-Optimize plugin to the latest available version (at least 3.2.12).\nWordfence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress WP-Optimize Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 3.2.12.","date":"2023-02-07"}],"impact":[]},{"uuid":"a3886be9dada3fce0f6ccf0b484fba09634ead6566d516e2bad4574e2ca40ef0","name":"WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 3.2.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1119","name":"CVE-2023-1119","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1119","description":"[en] The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.","date":"2023-07-10"},{"id":"5989f8bbded1154c69492721dc094ddf675232d5","name":"WordPress  WP-Optimize Plugin  < 3.2.13 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-optimize\/vulnerability\/wordpress-wp-optimize-plugin-3-2-13-reflected-xss-vulnerability","description":"Update the WordPress WP-Optimize plugin to the latest available version (at least 3.2.13).\nPaolo Elia  discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP-Optimize Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.2.13.","date":"2023-07-04"},{"id":"9dca0c9ecb28587085dfd633fadb1c731cef9ee1","name":"WP-Optimize <= 3.2.12 & SrbTransLatin <= 2.4 - Stored\/Reflected Cross-Site Scripting via Third Party Library","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/wp-optimize-3212-srbtranslatin-24-storedreflected-cross-site-scripting-via-third-party-library","description":"The WP-Optimize plugin and SrbTransLatin plugin for WordPress are vulnerable to Cross-Site Scripting via the 's' parameter in WP-Optimize in versions up to 3.2.12 and via post content in SrbTransLatin in versions up to, and including, 2.4 due to a third party library that strips some escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-07-04"},{"id":"2e78735a-a7fc-41fe-8284-45bf451eff06","name":"Multiple Plugins - Cross-Site Scripting From Third-party Library","link":"https:\/\/wpscan.com\/vulnerability\/2e78735a-a7fc-41fe-8284-45bf451eff06","description":"The plugins use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a804a1cf35152a938b5fa105d1e8454de794ed1b8e06c4fe24e763752ceb4e0f","name":"WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-3951","name":"WP-Optimize < 4.2.0 - Admin+ SQLi","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-3951","description":"The WP-Optimize  WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.","date":"0000-00-00"},{"id":"e05ed9d17b776896767dec79afc383b92291f10b","name":"WordPress WP-Optimize Plugin < 4.2.0 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-optimize\/vulnerability\/wordpress-wp-optimize-plugin-4-2-0-admin-sqli-vulnerability","description":"<p>WordPress WP-Optimize Plugin < 4.2.0 is vulnerable to SQL Injection<\/p><p>Software: WP-Optimize<\/p><p>Fixed in version 4.2.0 <\/p><p>Affected Version < 4.2.0<\/p><p>CVE: CVE-2025-3951<\/p>","date":"2025-06-02"},{"id":"63999124ec2b879a87d3fc82ead42e1dada2c953","name":"WP-Optimize <= 4.1.1 - Authenticated (Admin+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-optimize\/wp-optimize-411-authenticated-admin-sql-injection","description":"The WP-Optimize \u2013 Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-05-12"},{"id":"EUVD-2025-16607","name":"EUVD-2025-16607","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-16607","description":"The WP-Optimize  WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.","date":"2025-06-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"l","i":"n","a":"n","score":"4.1","severity":"m","exploitable":"2.3","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:L\/I:N\/A:N","score":"4.1","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"low","i":"none","a":"none","exploitable":"2.3","impact":"1.4"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a70a78ed366fc902ba7de8ea9bbdf836e7ca01dc838c23c8639bb38494a28c3e","name":"WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-2712","name":"WP-Optimize <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update and Image Manipulation","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2712","description":"The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes\/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly invoking `Updraft_Smush_Manager_Commands` methods without verifying user capabilities, nonce tokens, or the allowed commands whitelist that the normal AJAX handler (`updraft_smush_ajax`) enforces. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke admin-only Smush operations including reading log files (`get_smush_logs`), deleting all backup images (`clean_all_backup_images`), triggering bulk image processing (`process_bulk_smush`), and modifying Smush options (`update_smush_options`).","date":"0000-00-00"},{"id":"3e0a79d93ee9f5db4050a11aa41c855f9bda3cdf","name":"WP-Optimize <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update and Image Manipulation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-optimize\/wp-optimize-450-missing-authorization-to-authenticated-subscriber-plugin-settings-update-and-image-manipulation","description":"The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes\/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly invoking `Updraft_Smush_Manager_Commands` methods without verifying user capabilities, nonce tokens, or the allowed commands whitelist that the normal AJAX handler (`updraft_smush_ajax`) enforces. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke admin-only Smush operations including reading log files (`get_smush_logs`), deleting all backup images (`clean_all_backup_images`), triggering bulk image processing (`process_bulk_smush`), and modifying Smush options (`update_smush_options`).","date":"2026-04-09"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8049aea0cf23c8572ce04a057fca324cc3d05c4162173ffb61261677bf2878e3","name":"WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-7252","name":"CVE-2026-7252","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-7252","description":"[en] The WP-Optimize \u2013 Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4.5.2 This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is possible because 'original-file' is a public (non-protected) meta key \u2014 it does not begin with an underscore \u2014 allowing Authors to freely create or modify it on their own attachment posts via the standard Edit Media form or the REST API.","date":"2026-05-07"},{"id":"2cf8fa6ac12b5bf43aaee64bec0ede7d8f1c449f","name":"WP-Optimize <= 4.5.2 - Authenticated (Author+) Arbitrary File Deletion via 'original-file' Post Meta","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-optimize\/wp-optimize-452-authenticated-author-arbitrary-file-deletion-via-original-file-post-meta","description":"The WP-Optimize \u2013 Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4.5.2 This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is possible because 'original-file' is a public (non-protected) meta key \u2014 it does not begin with an underscore \u2014 allowing Authors to freely create or modify it on their own attachment posts via the standard Edit Media form or the REST API.","date":"2026-05-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"h","a":"h","score":"8.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:H","score":"8.1","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1778130422"}