# JCH Optimize <= 6.0.2 - Cross-Site Request Forgery to Cache Clearing, .htaccess Modification and Image Backup Deletion

- **ID:** WPSEC-2026-0772
- **Plugin:** JCH Optimize (`jch-optimize`), https://wordpress.org/plugins/jch-optimize/
- **Affected versions:** all versions before 6.1.0
- **Fixed in:** 6.1.0 (Update to 6.1.0 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L)
- **Weakness:** CWE-352
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-11)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/jch-optimize
- **Fix released:** 2026-10-10
- **Published:** 2026-10-11
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0772/

## Description

The JCH Optimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.2, due to missing nonce validation on several administrative tasks: Clean Cache, Generate New Cache Key, Order Plugin, Optimize .htaccess, Delete Backup Images and Restore Original Images. This makes it possible for unauthenticated attackers to clear the plugin's cache, regenerate the cache key, reorder plugins, write the plugin's rules to the site's .htaccess file, permanently delete backups of optimized images or restore the original images, granted they can trick a site administrator into performing an action such as clicking on a link.

## References

- https://wpsec.com/vuln/WPSEC-2026-0772/
- https://plugins.svn.wordpress.org/jch-optimize/tags/6.1.0/
- https://wordpress.org/plugins/jch-optimize/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0772/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
