WordPress Plugin Vulnerabilities

JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal

Description

The plugin does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root.

Proof of Concept

Affects Plugins

Fixed in 5.0.1

References

Classification

Type
TRAVERSAL
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Krugov Artyom
Submitter
Krugov Aryom
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-03 (about 1 day ago)
Added
2026-09-03 (about 1 day ago)
Last Updated
2026-09-03 (about 1 day ago)

Other