PT-2026-26877 · Charlycharm · Speedup Optimization
Nabil Irawan
·
Published
2026-03-21
·
Updated
2026-03-21
·
CVE-2026-4127
CVSS v3.1
5.3
Medium
| AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
The Speedup Optimization plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.5.9. The
speedup01 ajax enabled() function, which handles the wp ajax speedup01 enabled AJAX action, does not perform any capability check via current user can() and also lacks nonce verification. This is in contrast to other AJAX handlers in the same plugin (e.g., speedup01 ajax install iox and speedup01 ajax delete cache file) which properly check for install plugins and manage options capabilities respectively. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable or disable the site's optimization module by sending a POST request to admin-ajax.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Speedup Optimization