Impact
The vulnerability resides in the administrative image‑browsing component of the JCH Optimize WordPress plugin prior to version 5.0.1. Because the plugin fails to constrain the directory path supplied by an administrator, a high‑privilege user can request arbitrary paths relative to the site root. This path‑traversal flaw exposes directory listings and file names beyond the web root, potentially leaking sensitive configuration files or other proprietary data. The weakness is a classic path‑traversal defect (CWE‑22).
Affected Systems
WordPress installations using the JCH Optimize plugin versions 4.2.1 through 5.0.0 are affected. The flaw applies to single‑site admins and sub‑site administrators in multisite environments, as the plugin’s administrative interface is accessible to any user with those roles. No specific vendor name is provided beyond the plugin identifier; the issue exists on any host running the vulnerable plugin regardless of hosting environment.
Risk and Exploitability
The risk of exploitation is limited to authenticated, privileged users who have access to the plugin’s administrative interface; no exploitation path for unauthenticated users is documented. There is no evidence of code execution or privilege escalation beyond the information disclosure. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating a lower likelihood of widespread targeted attacks. However, because the flaw allows enumeration of files outside the web root, an attacker with high‑privilege access could potentially harvest sensitive files that could aid later attacks.
OpenCVE Enrichment