davidanderson Vulnerabilities and Affected Products
Vulnerabilities associated with WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance.
Products
Clear product- UpdraftPlus: WP Backup & Migration Plugin4 vulnerabilities
- Internal Link Juicer: SEO Auto Linker for WordPress3 vulnerabilities
- All-In-One Security (AIOS) – Security and Firewall2 vulnerabilities
- Redux Framework2 vulnerabilities
- WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance2 vulnerabilities
- Easy Updates Manager1 vulnerability
- Testimonial Slider1 vulnerability
- WPGet API – Connect to any external REST API1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-7252HIGH | WP-Optimize <= 4.5.2 - Authenticated (Author+) Arbitrary File Deletion via 'original-file' Post MetaThe WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4.5.2 This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is del… CWE-22May 7, 2026 | CVSS8.1v3.1 | EPSS0.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2712MEDIUM | WP-Optimize <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update and Image ManipulationThe WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly invoking `Updraft_Smush_Manager_Commands` methods without verifying user capabilities, nonce tokens, or the allowed commands whitelist that the normal AJAX handler (`updraft_smush_ajax`) enforces. This… CWE-863Apr 10, 2026 | CVSS5.4v3.1 | EPSS0.427% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |