The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site.
History

Mon, 07 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Jch Optimize Project
Jch Optimize Project jch Optimize
Wordpress
Wordpress wordpress
Vendors & Products Jch Optimize Project
Jch Optimize Project jch Optimize
Wordpress
Wordpress wordpress

Sun, 06 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 05 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site.
Title JCH Optimize < 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task Override
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-09-05T06:00:10.114Z

Updated: 2026-09-06T10:24:42.772Z

Reserved: 2026-09-02T16:26:43.553Z

Link: CVE-2026-84934

cve-icon Vulnrichment

Updated: 2026-09-06T10:24:06.932Z

cve-icon NVD

Status : Deferred

Published: 2026-09-05T07:17:14.690

Modified: 2026-09-08T19:15:18.627

Link: CVE-2026-84934

cve-icon Redhat

No data.