Impact
The vulnerability exists in WP Optimizer for WordPress versions up to 2.5.0, where the plugin incorrectly processes the 's' parameter during subquery detection. When the parameter value matches a SELECT pattern, it is wrapped in parentheses and inserted into the SQL string without escaping or quoting. Because the input contains no single quotes, WordPress’s automatic magic quoting does not protect it, enabling an attacker to inject arbitrary SQL subqueries. This flaw allows the execution of time‑based blind queries and the extraction of sensitive database content. The weakness is a classic SQL injection (CWE‑89).
Affected Systems
WordPress sites running the WP Optimizer – PageSpeed, Cache, Minify & Core Web Vitals plugin from vendor sh1zen are affected. All plugin releases from the earliest known version through 2.5.0 carry the flaw; upgrading to any release newer than 2.5.0 removes the vulnerability.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate risk, but the EPSS score of <1% and absence from the CISA KEV catalog suggest exploitation probability is currently low. Nonetheless, the attack requires administrator-level authentication, implying that privileged users can exploit the flaw. Once authenticated, an attacker could perform arbitrary data extraction or manipulation via crafted SQL subqueries.
OpenCVE Enrichment