Extension WordPress
Vulnérabilités WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance
Cette page rassemble les failles publiées pour WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance
5 fiches
WP-Optimize <= 4.5.2 – Authenticated (Author+) Arbitrary File Deletion via 'original-file' Post Meta
The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions…
*-4.5.2
4.5.3
06/05/2026
WP-Optimize <= 4.5.0 – Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update and Image Manipulation
The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler…
*-4.5.0
4.5.1
09/04/2026
WP-Optimize <= 4.1.1 – Authenticated (Admin+) SQL Injection
The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.1.1 due to insufficient escaping on the…
*-4.1.1
4.2.0
12/05/2025
WP-Optimize <= 3.2.12 & SrbTransLatin <= 2.4 – Stored/Reflected Cross-Site Scripting via Third Party Library
The WP-Optimize plugin and SrbTransLatin plugin for WordPress are vulnerable to Cross-Site Scripting via the 's' parameter in WP-Optimize in versions up to 3.2.12 and via post content in SrbTransLatin in versions up to, and including, 2.4 due…
[*, 3.2.13)
3.2.13
04/07/2023
WP-Optimize <= 3.2.11 – Cross-Site Request Forgery
The WP-Optimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.11. This is due to missing or incorrect nonce validation on the 'is_valid_request' function. This makes it possible for unauthenticated attackers…
*-3.2.11
3.2.12
06/02/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.