plugin

Wp Optimize Vulnerabilities

5 known security issues reported for the Wp Optimize WordPress plugin. Most recent disclosed May 6, 2026.

1 high 4 medium

Running Wp Optimize on your site? Check whether your installed version is affected.

Scan your site free

WP-Optimize <= 4.5.2 - Authenticated (Author+) Arbitrary File Deletion via 'original-file' Post Meta

high

The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4.5.2 This makes it possible...

CVSS:
8.1
Affected:
up to 4.5.2
Fixed in:
4.5.3
Disclosed:
May 6, 2026

CVE-2026-7252 on NVD →

WP-Optimize <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update and Image Manipulation

medium

The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly invoking `Updraft_Smu...

CVSS:
5.4
Affected:
up to 4.5.0
Fixed in:
4.5.1
Disclosed:
Apr 9, 2026

CVE-2026-2712 on NVD →

WP-Optimize <= 4.1.1 - Authenticated (Admin+) SQL Injection

medium

The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. T...

CVSS:
4.9
Affected:
up to 4.1.1
Fixed in:
4.2.0
Disclosed:
May 12, 2025

CVE-2025-3951 on NVD →

WP-Optimize <= 3.2.12 & SrbTransLatin <= 2.4 - Stored/Reflected Cross-Site Scripting via Third Party Library

medium

The WP-Optimize plugin and SrbTransLatin plugin for WordPress are vulnerable to Cross-Site Scripting via the 's' parameter in WP-Optimize in versions up to 3.2.12 and via post content in SrbTransLatin in versions up to, and including, 2.4 due to a third party library that strips some escaping. This makes it possible fo...

CVSS:
6.1
Affected:
up to 3.2.13
Fixed in:
3.2.13
Disclosed:
Jul 4, 2023

CVE-2023-1119 on NVD →

WP-Optimize <= 3.2.11 - Cross-Site Request Forgery

medium

The WP-Optimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.11. This is due to missing or incorrect nonce validation on the 'is_valid_request' function. This makes it possible for unauthenticated attackers to manage and modify cache and minification settings an...

CVSS:
6.5
Affected:
up to 3.2.11
Fixed in:
3.2.12
Disclosed:
Feb 6, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database