JCH Optimize <= 6.0.2 - Cross-Site Request Forgery to Cache Clearing, .htaccess Modification and Image Backup Deletion
- ID
- WPSEC-2026-0772
- Plugin
- JCH Optimize (jch-optimize)
- Affected
- all versions before 6.1.0
- Remediation
- Update to 6.1.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
- Weakness
- CWE-352
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-11
- Attack surface
- JCH Optimize on WPSec AttackSurface
- Fix released
- Published
Description
The JCH Optimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.2, due to missing nonce validation on several administrative tasks: Clean Cache, Generate New Cache Key, Order Plugin, Optimize .htaccess, Delete Backup Images and Restore Original Images. This makes it possible for unauthenticated attackers to clear the plugin's cache, regenerate the cache key, reorder plugins, write the plugin's rules to the site's .htaccess file, permanently delete backups of optimized images or restore the original images, granted they can trick a site administrator into performing an action such as clicking on a link.
References
- https://wpsec.com/vuln/WPSEC-2026-0772/
- https://plugins.svn.wordpress.org/jch-optimize/tags/6.1.0/
- https://wordpress.org/plugins/jch-optimize/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS