PT-2026-49072 · Aurelienlws · Lws Optimize – All-In-One Speed Booster & Cache Tools

Omar Elshopky

·

Published

2026-06-13

·

Updated

2026-06-13

·

CVE-2026-12089

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.3.19. This is due to the combine current css() function trusting values harvested from page HTML and converting same-site URLs to absolute filesystem paths before reading them with file get contents()/MinifyCSS::add(), without enforcing that the resolved path stay within ABSPATH or have a .css extension. This makes it possible for authenticated attackers, with Editor-level access and above, to read arbitrary files.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-12089

Affected Products

Lws Optimize – All-In-One Speed Booster & Cache Tools