Description
Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer wp-optimizer allows SQL Injection.This issue affects WP Optimizer: from n/a through <= 2.5.0.
Published: 2025-06-27
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The defect is a Cross‑Site Request Forgery flaw that allows an attacker to craft a malicious request that the WordPress site will perform on behalf of a logged‑in user. The vulnerability can lead to arbitrary SQL query execution, potentially enabling full compromise of the database. Such an injection can allow attackers to read, modify, or delete sensitive data and, in the worst case, pivot to further attacks against the host. The weakness is identified as CWE‑352.

Affected Systems

The problem exists in the sh1zen WP Optimizer plugin, all released versions through and including 2.5.0. Users running older or the listed versions are affected, regardless of the WordPress core version. No other products or vendors are reported to be impacted by this weakness.

Risk and Exploitability

The CVSS score of 9.6 classifies the flaw as critical, and the EPSS score of less than 1% indicates that exploitation is currently considered unlikely, though the risk remains high if the plugin is used. The vulnerability is not listed in the CISA KeV catalog, but its severity warrants immediate attention. The likely attack vector is a CSRF request originating from any page that can be loaded by a logged‑in administrator, as the description infers that an attacker can cause the site to execute arbitrary SQL via that flaw. Proper access control and a valid CSRF token are required to prevent exploitation, but the current implementation fails to enforce them.

Generated by OpenCVE AI on April 30, 2026 at 17:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest available version of WP Optimizer (version 2.5.x or later) as the vendor upgrade removes the CSRF‑SQL injection flaw.
  • If an upgrade cannot be performed immediately, disable the WP Optimizer plugin to eliminate the attack surface until a fix is applied.
  • Review database tables for unexpected entries or modifications and consider restoring from a clean backup if compromise is suspected.

Generated by OpenCVE AI on April 30, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28511 Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer allows SQL Injection. This issue affects WP Optimizer: from n/a through 2.3.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer allows SQL Injection. This issue affects WP Optimizer: from n/a through 2.3.6. Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer wp-optimizer allows SQL Injection.This issue affects WP Optimizer: from n/a through <= 2.5.0.
Title WordPress WP Optimizer plugin <= 2.3.6 - Cross Site Request Forgery (CSRF) Vulnerability WordPress WP Optimizer plugin <= 2.5.0 - Cross Site Request Forgery (CSRF) vulnerability
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L'}


Fri, 27 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Jun 2025 13:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer allows SQL Injection. This issue affects WP Optimizer: from n/a through 2.3.6.
Title WordPress WP Optimizer plugin <= 2.3.6 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:23.463Z

Reserved: 2025-06-27T11:59:14.508Z

Link: CVE-2025-53314

cve-icon Vulnrichment

Updated: 2025-06-27T17:24:05.720Z

cve-icon NVD

Status : Deferred

Published: 2025-06-27T14:15:53.857

Modified: 2026-04-23T15:32:28.673

Link: CVE-2025-53314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T17:15:42Z

Weaknesses