# JCH Optimize <= 6.0.2 - Open Redirect via 'return' Parameter

- **ID:** WPSEC-2026-0771
- **Plugin:** JCH Optimize (`jch-optimize`), https://wordpress.org/plugins/jch-optimize/
- **Affected versions:** all versions before 6.1.0
- **Fixed in:** 6.1.0 (Update to 6.1.0 or later.)
- **Severity:** Medium 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-601
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-11)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/jch-optimize
- **Fix released:** 2026-10-10
- **Published:** 2026-10-11
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0771/

## Description

The JCH Optimize plugin for WordPress is vulnerable to Open Redirect via the 'return' parameter of the Clean Cache task in all versions up to, and including, 6.0.2 due to the base64-decoded value being passed to wp_redirect without validating the destination. Because the task also lacked nonce verification, this makes it possible for unauthenticated attackers to redirect a logged-in administrator to arbitrary external sites, granted they can trick the administrator into clicking a crafted link.

## References

- https://wpsec.com/vuln/WPSEC-2026-0771/
- https://plugins.svn.wordpress.org/jch-optimize/tags/6.1.0/
- https://wordpress.org/plugins/jch-optimize/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0771/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
