Description
The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is due to an unsafe subquery-detection branch in the Query::parse_key_compare_field() method that, when the user-supplied value matches the regex ^[(\s]*SELECT\s+, wraps the value in parentheses and embeds it directly into the SQL string without any escaping or quoting. While the normal LIKE code path correctly uses esc_sql($wpdb->esc_like(...)) and wraps the value in single quotes, this branch completely bypasses those protections. Because the attack payload (SELECT ...) contains no single quotes, WordPress's wp_magic_quotes() provides no protection. This makes it possible for authenticated attackers with administrator-level access to inject arbitrary SQL subqueries — including time-based blind payloads — that can be used to extract sensitive information from the database.
Published: 2026-09-19
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated SQL Injection (CWE-89)
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists in WP Optimizer for WordPress versions up to 2.5.0, where the plugin incorrectly processes the 's' parameter during subquery detection. When the parameter value matches a SELECT pattern, it is wrapped in parentheses and inserted into the SQL string without escaping or quoting. Because the input contains no single quotes, WordPress’s automatic magic quoting does not protect it, enabling an attacker to inject arbitrary SQL subqueries. This flaw allows the execution of time‑based blind queries and the extraction of sensitive database content. The weakness is a classic SQL injection (CWE‑89).

Affected Systems

WordPress sites running the WP Optimizer – PageSpeed, Cache, Minify & Core Web Vitals plugin from vendor sh1zen are affected. All plugin releases from the earliest known version through 2.5.0 carry the flaw; upgrading to any release newer than 2.5.0 removes the vulnerability.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate risk, but the EPSS score of <1% and absence from the CISA KEV catalog suggest exploitation probability is currently low. Nonetheless, the attack requires administrator-level authentication, implying that privileged users can exploit the flaw. Once authenticated, an attacker could perform arbitrary data extraction or manipulation via crafted SQL subqueries.

Generated by OpenCVE AI on September 19, 2026 at 23:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Optimizer to a version newer than 2.5.0.
  • If an upgrade cannot be performed, disable or delete the plugin to remove the vulnerability vector.
  • Restrict administrator access by enforcing multi‑factor authentication and limiting user roles; regularly audit and monitor WordPress admin logs for suspicious activity.

Generated by OpenCVE AI on September 19, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Sh1zen
Sh1zen wp Optimizer – Pagespeed, Cache, Minify & Core Web Vitals
Wordpress
Wordpress wordpress
Vendors & Products Sh1zen
Sh1zen wp Optimizer – Pagespeed, Cache, Minify & Core Web Vitals
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is due to an unsafe subquery-detection branch in the Query::parse_key_compare_field() method that, when the user-supplied value matches the regex ^[(\s]*SELECT\s+, wraps the value in parentheses and embeds it directly into the SQL string without any escaping or quoting. While the normal LIKE code path correctly uses esc_sql($wpdb->esc_like(...)) and wraps the value in single quotes, this branch completely bypasses those protections. Because the attack payload (SELECT ...) contains no single quotes, WordPress's wp_magic_quotes() provides no protection. This makes it possible for authenticated attackers with administrator-level access to inject arbitrary SQL subqueries — including time-based blind payloads — that can be used to extract sensitive information from the database.
Title WP Optimizer <= 2.5.0 - Authenticated (Administrator+) SQL Injection via 's' Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Sh1zen Wp Optimizer – Pagespeed, Cache, Minify & Core Web Vitals
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:23.686Z

Reserved: 2026-04-14T18:07:55.496Z

Link: CVE-2026-6295

cve-icon Vulnrichment

Updated: 2026-09-19T13:53:33.152Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:54.340

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-6295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:33Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')