PT-2026-49072 · Aurelienlws · Lws Optimize – All-In-One Speed Booster & Cache Tools
Omar Elshopky
·
Published
2026-06-13
·
Updated
2026-06-13
·
CVE-2026-12089
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.3.19. This is due to the combine current css() function trusting values harvested from page HTML and converting same-site URLs to absolute filesystem paths before reading them with file get contents()/MinifyCSS::add(), without enforcing that the resolved path stay within ABSPATH or have a .css extension. This makes it possible for authenticated attackers, with Editor-level access and above, to read arbitrary files.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lws Optimize – All-In-One Speed Booster & Cache Tools