Description
WordPress Plugin RapidLoad Power-Up for Autoptimize is prone to multiple vulnerabilities, including security bypass and cross-site request forgery vulnerabilities. Exploiting these issues could allow an attacker to perform otherwise restricted actions and subsequently modify the plugins cache, add a new license, delete logs files, update cache rules, or to perform certain administrative actions and gain unauthorized access to the affected application. WordPress Plugin RapidLoad Power-Up for Autoptimize version 1.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.2 or latest
References
Related Vulnerabilities
Oracle Database Server CVE-2019-2749 Vulnerability (CVE-2019-2749)
WordPress Plugin Calendar Event Multi View Security Bypass (1.4.13)
WordPress Plugin Sell Downloads Cross-Site Scripting (1.0.86)
MySQL CVE-2018-3278 Vulnerability (CVE-2018-3278)
Riot.js Resource Management Errors Vulnerability (CVE-2016-10527)