Extension WordPress
Vulnérabilités RapidLoad AI – Optimize Web Vitals Automatically
Cette page rassemble les failles publiées pour RapidLoad AI – Optimize Web Vitals Automatically, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de RapidLoad AI – Optimize Web Vitals Automatically
20 fiches
RapidLoad <= 2.4.4 – Missing Authorization
The RapidLoad plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the rapidload_switch_test_mode() function in versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with subscriber-level access and…
*-2.4.4
2.4.5
03/02/2025
RapidLoad – Optimize Web Vitals Automatically <= 2.4.4 – Missing Authorization to Authenticated (Subscriber+) Limited Setting Reset
The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_deactivate() function in all versions up to, and including, 2.4.4. This makes it…
*-2.4.4
2.4.5
31/01/2025
RapidLoad – Optimize Web Vitals Automatically <= 2.4.2 – Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification and SQL Injection
The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the uucss_data, update_rapidload_settings, wp_ajax_update_htaccess_file, uucss_update_rule, upload_rules, get_all_rules, update_titan_settings, preload_page, and…
*-2.4.2
2.4.3
10/12/2024
RapidLoad Power-Up for Autoptimize <= 2.2.11 – Unauthenticated Server-Side Request Forgery
The RapidLoad 2.2 – Speed Monster in One Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.11. This makes it possible for unauthenticated attackers to make web requests to…
*-2.2.11
2.2.12
05/04/2024
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Cross-Site Request Forgery
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible…
*-1.7.1
1.7.2
17/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Missing Authorization in 'queue_posts'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the queue_posts function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Missing Authorization in 'ucss_connect'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the ucss_connect function in versions up to, and including, 1.7.1. This makes it possible for authenticated…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Cross-Site Request Forgery via 'ajax_deactivate'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate function. This makes it possible…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Cross-Site Request Forgery via 'queue_posts'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the queue_posts function. This makes it possible…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Missing Authorization in 'ajax_deactivate'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the ajax_deactivate function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Cross-Site Request Forgery via 'clear_page_cache'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_page_cache function. This makes it possible…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Missing Authorization in 'clear_uucss_logs'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Cross-Site Request Forgery via 'ucss_connect'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ucss_connect function. This makes it possible…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Cross-Site Request Forgery via 'clear_uucss_logs'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_uucss_logs function. This makes it possible…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Missing Authorization in 'clear_page_cache'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_page_cache function in versions up to, and including, 1.7.1. This makes it possible for authenticated…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Cross-Site Request Forgery via 'uucss_update_rule'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the uucss_update_rule function. This makes it possible…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Missing Authorization in 'attach_rule'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the attach_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Missing Authorization in 'uucss_update_rule'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the uucss_update_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.7.1 – Cross-Site Request Forgery via 'attach_rule'
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the attach_rule function. This makes it possible…
*-1.7.1
1.7.2
10/03/2023
RapidLoad Power-Up for Autoptimize <= 1.6.35 – Authenticated (Subscriber+) SQL Injection
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to SQL Injection via the rule_id parameter in versions up to, and including, 1.6.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-1.6.35
1.6.36
20/01/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.