Extension WordPress

Vulnérabilités Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization

Cette page rassemble les failles publiées pour Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
0Critiques
8Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization

8 fiches

CVE-2026-57673 Élevée · 7,2
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization

Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.7 – Unauthenticated Stored Cross-Site Scripting

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.7 due to insufficient input…

Versions affectées

*-4.2.7

Correctif

4.2.8

Publication

30/06/2026

CVE-2026-11784 Moyenne · 4,3
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization

Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 – Cross-Site Request Forgery via 'optml_replace_file' AJAX Action

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.6. This is due…

Versions affectées

*-4.2.6

Correctif

4.2.7

Publication

17/06/2026

CVE-2026-5217 Élevée · 7,2
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization

Optimole <= 4.2.2 – Unauthenticated Stored Cross-Site Scripting via Srcset Descriptor Parameter

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.2. This is due…

Versions affectées

*-4.2.2

Correctif

4.2.3

Publication

10/04/2026

CVE-2026-5226 Moyenne · 6,1
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization

Optimole <= 4.2.3 – Reflected Cross-Site Scripting via Page Profiler URL

The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL paths in versions up to, and including, 4.2.3 This is due to insufficient output escaping on user-supplied URL paths…

Versions affectées

*-4.2.3

Correctif

4.2.4

Publication

10/04/2026

CVE-2025-11519 Moyenne · 4,3
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization

Image optimization service by Optimole <= 4.1.0 – Insecure Direct Object Reference to Authenticated (Author+) Media Offload

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the…

Versions affectées

*-4.1.0

Correctif

4.1.1

Publication

17/10/2025

CVE-2024-4636 Moyenne · 6,4
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization

Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF <= 3.12.10 – Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload

The Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘allow_meme_types’ function in versions up to, and including, 3.12.10 due to insufficient input sanitization…

Versions affectées

*-3.12.10

Correctif

3.13.0

Publication

14/05/2024

CVE-2024-1047 Moyenne · 5,3
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization

ThemeIsle SDK <= Various Versions – Missing Authorization

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to…

Versions affectées

*-3.12.4

Correctif

3.12.5

Publication

01/02/2024

CVE-2022-0969 Moyenne · 4,8
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization

Image optimization & Lazy Load <= 3.3.1 – Admin+ Stored Cross-Site Scripting

The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload background images for selectors" settings, which could allow high privilege users such as admin to perform Cross-Site scripting attacks…

Versions affectées

[*, 3.3.2)

Correctif

3.3.2

Publication

21/03/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités