{
 "id": "WPSEC-2026-0772",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0772/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0772/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0772/index.md",
 "title": "JCH Optimize <= 6.0.2 - Cross-Site Request Forgery to Cache Clearing, .htaccess Modification and Image Backup Deletion",
 "description": "The JCH Optimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.2, due to missing nonce validation on several administrative tasks: Clean Cache, Generate New Cache Key, Order Plugin, Optimize .htaccess, Delete Backup Images and Restore Original Images. This makes it possible for unauthenticated attackers to clear the plugin's cache, regenerate the cache key, reorder plugins, write the plugin's rules to the site's .htaccess file, permanently delete backups of optimized images or restore the original images, granted they can trick a site administrator into performing an action such as clicking on a link.",
 "plugin": {
  "slug": "jch-optimize",
  "name": "JCH Optimize",
  "full_name": "JCH Optimize",
  "wordpress_org": "https://wordpress.org/plugins/jch-optimize/",
  "advisories_url": "https://wpsec.com/vuln/plugin/jch-optimize/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/jch-optimize"
 },
 "type": "CSRF",
 "cwe": [
  "CWE-352"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.4,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "6.1.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 6.1.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "6.1.0",
 "remediation": "Update to 6.1.0 or later.",
 "fix_released": "2026-10-10T16:32:33+00:00",
 "published": "2026-10-11T16:42:00+00:00",
 "updated": "2026-10-11T11:41:36.706682+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0772/",
  "https://plugins.svn.wordpress.org/jch-optimize/tags/6.1.0/",
  "https://wordpress.org/plugins/jch-optimize/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/jch-optimize",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-11"
 }
}