Vulnerabilities / JCH Optimize / WPSEC-2026-0771

JCH Optimize <= 6.0.2 - Open Redirect via 'return' Parameter

Medium 6.1 CWE-601Fixed in 6.1.0
ID
WPSEC-2026-0771
Plugin
JCH Optimize (jch-optimize)
Affected
all versions before 6.1.0
Remediation
Update to 6.1.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness
CWE-601
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-11
Attack surface
JCH Optimize on WPSec AttackSurface
Fix released
Published

Description

The JCH Optimize plugin for WordPress is vulnerable to Open Redirect via the 'return' parameter of the Clean Cache task in all versions up to, and including, 6.0.2 due to the base64-decoded value being passed to wp_redirect without validating the destination. Because the task also lacked nonce verification, this makes it possible for unauthenticated attackers to redirect a logged-in administrator to arbitrary external sites, granted they can trick the administrator into clicking a crafted link.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0