Vulnerabilities / JCH Optimize / WPSEC-2026-0772

JCH Optimize <= 6.0.2 - Cross-Site Request Forgery to Cache Clearing, .htaccess Modification and Image Backup Deletion

Medium 5.4 CWE-352Fixed in 6.1.0
ID
WPSEC-2026-0772
Plugin
JCH Optimize (jch-optimize)
Affected
all versions before 6.1.0
Remediation
Update to 6.1.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Weakness
CWE-352
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-11
Attack surface
JCH Optimize on WPSec AttackSurface
Fix released
Published

Description

The JCH Optimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.2, due to missing nonce validation on several administrative tasks: Clean Cache, Generate New Cache Key, Order Plugin, Optimize .htaccess, Delete Backup Images and Restore Original Images. This makes it possible for unauthenticated attackers to clear the plugin's cache, regenerate the cache key, reorder plugins, write the plugin's rules to the site's .htaccess file, permanently delete backups of optimized images or restore the original images, granted they can trick a site administrator into performing an action such as clicking on a link.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0