Description
WordPress Plugin RapidLoad Power-Up for Autoptimize is prone to multiple vulnerabilities, including security bypass and cross-site request forgery vulnerabilities. Exploiting these issues could allow an attacker to perform otherwise restricted actions and subsequently modify the plugins cache, add a new license, delete logs files, update cache rules, or to perform certain administrative actions and gain unauthorized access to the affected application. WordPress Plugin RapidLoad Power-Up for Autoptimize version 1.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.2 or latest
References
Related Vulnerabilities
WordPress Plugin Blue Wrench Video Widget Cross-Site Scripting (2.1.0)
WordPress Plugin Gutenberg Blocks by WordPress Download Manager Cross-Site Scripting (2.1.8)
WordPress Plugin Slimstat Analytics Security Bypass (5.0.5.1)
Atlassian Jira Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-20408)
Zope Web Application Server Other Vulnerability (CVE-2006-3458)