WordPress Plugin Vulnerabilities
JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal
Description
The plugin does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
TRAVERSAL
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Krugov Artyom
Submitter
Krugov Aryom
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-03 (about 1 day ago)
Added
2026-09-03 (about 1 day ago)
Last Updated
2026-09-03 (about 1 day ago)