Extension WordPress
Vulnérabilités Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
Cette page rassemble les failles publiées pour Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
8 fiches
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.7 – Unauthenticated Stored Cross-Site Scripting
The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.7 due to insufficient input…
*-4.2.7
4.2.8
30/06/2026
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 – Cross-Site Request Forgery via 'optml_replace_file' AJAX Action
The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.6. This is due…
*-4.2.6
4.2.7
17/06/2026
Optimole <= 4.2.2 – Unauthenticated Stored Cross-Site Scripting via Srcset Descriptor Parameter
The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.2. This is due…
*-4.2.2
4.2.3
10/04/2026
Optimole <= 4.2.3 – Reflected Cross-Site Scripting via Page Profiler URL
The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL paths in versions up to, and including, 4.2.3 This is due to insufficient output escaping on user-supplied URL paths…
*-4.2.3
4.2.4
10/04/2026
Image optimization service by Optimole <= 4.1.0 – Insecure Direct Object Reference to Authenticated (Author+) Media Offload
The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the…
*-4.1.0
4.1.1
17/10/2025
Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF <= 3.12.10 – Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload
The Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘allow_meme_types’ function in versions up to, and including, 3.12.10 due to insufficient input sanitization…
*-3.12.10
3.13.0
14/05/2024
ThemeIsle SDK <= Various Versions – Missing Authorization
Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to…
*-3.12.4
3.12.5
01/02/2024
Image optimization & Lazy Load <= 3.3.1 – Admin+ Stored Cross-Site Scripting
The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload background images for selectors" settings, which could allow high privilege users such as admin to perform Cross-Site scripting attacks…
[*, 3.3.2)
3.3.2
21/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.