The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site.
History

Sat, 05 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site.
Title JCH Optimize < 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task Override
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-05T06:00:10.114Z

Reserved: 2026-09-02T16:26:43.553Z

Link: CVE-2026-84934

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-05T07:17:14.690

Modified: 2026-09-05T07:17:14.690

Link: CVE-2026-84934

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.