Description
WordPress Plugin RapidLoad Power-Up for Autoptimize is prone to multiple vulnerabilities, including security bypass and cross-site request forgery vulnerabilities. Exploiting these issues could allow an attacker to perform otherwise restricted actions and subsequently modify the plugins cache, add a new license, delete logs files, update cache rules, or to perform certain administrative actions and gain unauthorized access to the affected application. WordPress Plugin RapidLoad Power-Up for Autoptimize version 1.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.2 or latest
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-2353)
MySQL CVE-2021-2293 Vulnerability (CVE-2021-2293)
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-33338)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery SQL Injection (1.5.30)