PT-2026-38342 · WordPress · Wp-Optimize

Ly Hoang

·

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2026-7252

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance versions prior to 4.5.3
Description Insufficient file path validation in the unscheduled original file deletion() function allows authenticated attackers with author-level access or higher to delete arbitrary files on the server. This occurs because original-file is a public meta key that can be modified by authors via the REST API or the standard Edit Media form. Deleting critical files, such as 'wp-config.php', can lead to remote code execution.
Recommendations Update the plugin to a version later than 4.5.2.

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7252

Affected Products

Wp-Optimize