RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 2.4.5
unknown
[en] Missing Authorization vulnerability in Shakeeb Sadikeen RapidLoad allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RapidLoad: from n/a through 2.4.4.
- Affected:
- up to 2.4.5
- Fixed in:
- 2.4.5
- Disclosed:
- Mar 27, 2025
CVE-2025-22665 on NVD →
RapidLoad <= 2.4.4 - Missing Authorization
medium
The RapidLoad plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the rapidload_switch_test_mode() function in versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to switch to test mode.
- CVSS:
- 4.3
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.5
- Disclosed:
- Feb 3, 2025
CVE-2025-22665 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 2.4.5
unknown
[en] The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_deactivate() function in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access...
- Affected:
- up to 2.4.5
- Fixed in:
- 2.4.5
- Disclosed:
- Feb 1, 2025
CVE-2024-13651 on NVD →
RapidLoad – Optimize Web Vitals Automatically <= 2.4.4 - Missing Authorization to Authenticated (Subscriber+) Limited Setting Reset
medium
The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_deactivate() function in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and...
- CVSS:
- 4.3
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.5
- Disclosed:
- Jan 31, 2025
CVE-2024-13651 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 2.4.3
unknown
[en] The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the uucss_data, update_rapidload_settings, wp_ajax_update_htaccess_file, uucss_update_rule, upload_rules, get_all_rules, update_titan_set...
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.3
- Disclosed:
- Dec 11, 2024
CVE-2024-11840 on NVD →
RapidLoad – Optimize Web Vitals Automatically <= 2.4.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification and SQL Injection
high
The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the uucss_data, update_rapidload_settings, wp_ajax_update_htaccess_file, uucss_update_rule, upload_rules, get_all_rules, update_titan_settings...
- CVSS:
- 7.1
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.3
- Disclosed:
- Dec 10, 2024
CVE-2024-11840 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 2.2.12
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize.This issue affects RapidLoad Power-Up for Autoptimize: from n/a through 2.2.11.
- Affected:
- up to 2.2.12
- Fixed in:
- 2.2.12
- Disclosed:
- Apr 7, 2024
CVE-2024-31288 on NVD →
RapidLoad Power-Up for Autoptimize <= 2.2.11 - Unauthenticated Server-Side Request Forgery
high
The RapidLoad 2.2 – Speed Monster in One Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.11. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which can be used to query...
- CVSS:
- 7.2
- Affected:
- up to 2.2.11
- Fixed in:
- 2.2.12
- Disclosed:
- Apr 5, 2024
CVE-2024-31288 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.6.36
unknown
[en] Auth. (subscriber+) SQL Injection (SQLi) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize plugin <= 1.6.35 versions.
- Affected:
- up to 1.6.36
- Fixed in:
- 1.6.36
- Disclosed:
- Jun 22, 2023
CVE-2022-47593 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Cross-Site Request Forgery
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthenticated attackers to invoke those functions, via forged request gr...
- CVSS:
- 6.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 17, 2023
CVE-2023-1472 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthenticated attackers to invoke those functions, via forged reque...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 17, 2023
CVE-2023-1472 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Cross-Site Request Forgery via 'clear_uucss_logs'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_uucss_logs function. This makes it possible for unauthenticated attackers to clear plugin logs via a forged r...
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1340 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Missing Authorization in 'uucss_update_rule'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the uucss_update_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to update caching rules.
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1339 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Missing Authorization in 'attach_rule'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the attach_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify cache rules.
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1338 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Cross-Site Request Forgery via 'uucss_update_rule'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the uucss_update_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a...
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1344 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Missing Authorization in 'clear_page_cache'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_page_cache function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete the plugin's cache.
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1333 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Cross-Site Request Forgery via 'attach_rule'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the attach_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forge...
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1343 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Missing Authorization in 'queue_posts'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the queue_posts function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify the plugin's cache...
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1334 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Cross-Site Request Forgery via 'ucss_connect'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ucss_connect function. This makes it possible for unauthenticated attackers to connect the site to a new license ke...
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1342 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Cross-Site Request Forgery via 'ajax_deactivate'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate function. This makes it possible for unauthenticated attackers to turn off caching via a forged req...
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1341 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Missing Authorization in 'clear_uucss_logs'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete plugin log files.
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1337 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Cross-Site Request Forgery via 'clear_page_cache'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_page_cache function. This makes it possible for unauthenticated attackers to clear the plugin's cache via a f...
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1346 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Missing Authorization in 'ajax_deactivate'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the ajax_deactivate function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to disable caching.
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1336 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Cross-Site Request Forgery via 'queue_posts'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the queue_posts function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forge...
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1345 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.7.1 - Missing Authorization in 'ucss_connect'
medium
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the ucss_connect function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to connect a new licens...
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1335 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete plugin log files.
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1337 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the queue_posts function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify the plugin's...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1334 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_uucss_logs function. This makes it possible for unauthenticated attackers to clear plugin logs via a for...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1340 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_page_cache function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete the plugin's c...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1333 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the uucss_update_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1344 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_page_cache function. This makes it possible for unauthenticated attackers to clear the plugin's cache vi...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1346 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the attach_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1343 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the uucss_update_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to update caching ru...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1339 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the queue_posts function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1345 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the ucss_connect function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to connect a new l...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1335 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the attach_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify cache rules.
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1338 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the ajax_deactivate function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to disable caching.
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1336 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate function. This makes it possible for unauthenticated attackers to turn off caching via a forge...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1341 on NVD →
RapidLoad AI – Optimize Web Vitals Automatically [unusedcss] < 1.7.2
unknown
[en] The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ucss_connect function. This makes it possible for unauthenticated attackers to connect the site to a new licen...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 10, 2023
CVE-2023-1342 on NVD →
RapidLoad Power-Up for Autoptimize <= 1.6.35 - Authenticated (Subscriber+) SQL Injection
high
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to SQL Injection via the rule_id parameter in versions up to, and including, 1.6.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated...
- CVSS:
- 7.2
- Affected:
- up to 1.6.35
- Fixed in:
- 1.6.36
- Disclosed:
- Jan 20, 2023
CVE-2022-47593 on NVD →