Speed Optimizer <= 7.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes
medium
The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with con...
- CVSS:
- 6.4
- Affected:
- up to 7.8.0
- Fixed in:
- 7.8.1
- Disclosed:
- Aug 18, 2026
CVE-2026-15421 on NVD →
Speed Optimizer <= 7.4.6 - Missing Authorization via purge_on_other_events()
medium
The Speed Optimizer – The All-In-One WordPress Performance-Boosting Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the purge_on_other_events() function in all versions up to, and including, 7.4.6. This makes it possible for unauthenticated attackers t...
- CVSS:
- 5.3
- Affected:
- up to 7.4.6
- Fixed in:
- 7.5.0
- Disclosed:
- Apr 15, 2024
CVE-2024-32532 on NVD →
SiteGround Optimizer <= 5.0.12 - Missing Authorization
critical
The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0.12 due to incorrect use of an access control attribute on the switch_php function called via the /switch-php REST API route. This allows att...
- CVSS:
- 9.8
- Affected:
- up to 5.0.13
- Fixed in:
- 5.0.13
- Disclosed:
- Mar 14, 2019
CVE-2019-25217 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database