WP-Optimize <= 4.5.2 - Authenticated (Author+) Arbitrary File Deletion via 'original-file' Post Meta
high
The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4.5.2 This makes it possible...
- CVSS:
- 8.1
- Affected:
- up to 4.5.2
- Fixed in:
- 4.5.3
- Disclosed:
- May 6, 2026
CVE-2026-7252 on NVD →
WP-Optimize <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update and Image Manipulation
medium
The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly invoking `Updraft_Smu...
- CVSS:
- 5.4
- Affected:
- up to 4.5.0
- Fixed in:
- 4.5.1
- Disclosed:
- Apr 9, 2026
CVE-2026-2712 on NVD →
WP-Optimize <= 4.1.1 - Authenticated (Admin+) SQL Injection
medium
The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. T...
- CVSS:
- 4.9
- Affected:
- up to 4.1.1
- Fixed in:
- 4.2.0
- Disclosed:
- May 12, 2025
CVE-2025-3951 on NVD →
WP-Optimize <= 3.2.12 & SrbTransLatin <= 2.4 - Stored/Reflected Cross-Site Scripting via Third Party Library
medium
The WP-Optimize plugin and SrbTransLatin plugin for WordPress are vulnerable to Cross-Site Scripting via the 's' parameter in WP-Optimize in versions up to 3.2.12 and via post content in SrbTransLatin in versions up to, and including, 2.4 due to a third party library that strips some escaping. This makes it possible fo...
- CVSS:
- 6.1
- Affected:
- up to 3.2.13
- Fixed in:
- 3.2.13
- Disclosed:
- Jul 4, 2023
CVE-2023-1119 on NVD →
WP-Optimize <= 3.2.11 - Cross-Site Request Forgery
medium
The WP-Optimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.11. This is due to missing or incorrect nonce validation on the 'is_valid_request' function. This makes it possible for unauthenticated attackers to manage and modify cache and minification settings an...
- CVSS:
- 6.5
- Affected:
- up to 3.2.11
- Fixed in:
- 3.2.12
- Disclosed:
- Feb 6, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database