Vulnerabilities (CVE)

Filtered by vendor Updraftplus Subscribe
Filtered by product Wp-optimize
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-3951 1 Updraftplus 1 Wp-optimize 2025-06-09 N/A 4.1 MEDIUM
The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.
CVE-2023-1119 2 Srbtranslatin Project, Updraftplus 2 Srbtranslatin, Wp-optimize 2025-01-06 N/A 6.1 MEDIUM
The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.