Description
WordPress Plugin RapidLoad Power-Up for Autoptimize is prone to multiple vulnerabilities, including security bypass and cross-site request forgery vulnerabilities. Exploiting these issues could allow an attacker to perform otherwise restricted actions and subsequently modify the plugins cache, add a new license, delete logs files, update cache rules, or to perform certain administrative actions and gain unauthorized access to the affected application. WordPress Plugin RapidLoad Power-Up for Autoptimize version 1.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.2 or latest
References
Related Vulnerabilities
WordPress Plugin Kama Click Counter SQL Injection (3.4.9)
MySQL CVE-2020-14836 Vulnerability (CVE-2020-14836)
WordPress Plugin Goolytics-Simple Google Analytics Cross-Site Scripting (1.1.1)
MySQL CVE-2021-2160 Vulnerability (CVE-2021-2160)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-50723)