PT-2026-26877 · Charlycharm · Speedup Optimization

Nabil Irawan

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2026-4127

CVSS v3.1

5.3

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The Speedup Optimization plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.5.9. The speedup01 ajax enabled() function, which handles the wp ajax speedup01 enabled AJAX action, does not perform any capability check via current user can() and also lacks nonce verification. This is in contrast to other AJAX handlers in the same plugin (e.g., speedup01 ajax install iox and speedup01 ajax delete cache file) which properly check for install plugins and manage options capabilities respectively. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable or disable the site's optimization module by sending a POST request to admin-ajax.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-4127

Affected Products

Speedup Optimization