Executive brief
WP-Optimize, a popular WordPress plugin used for site optimization and image compression, contains a security flaw that allows low-level users to perform administrative actions. An attacker with a basic subscriber account could delete image backups, modify plugin settings, or view system logs. This could lead to data loss or unauthorized changes to how the website handles its media and performance settings.
Technical details
The WP-Optimize plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks in the `receive_heartbeat()` function within `includes/class-wp-optimize-heartbeat.php`. The Heartbeat handler directly invokes `Updraft_Smush_Manager_Commands` methods without verifying user permissions or validating against the allowed commands whitelist used by the standard AJAX handler. Authenticated attackers with Subscriber-level access or higher can exploit this to execute admin-only operations. Impacted actions include reading log files (`get_smush_logs`), deleting backup images (`clean_all_backup_images`), triggering bulk image processing (`process_bulk_smush`), and modifying Smush configuration (`update_smush_options`).
Affected products
- UpdraftPlus WP-Optimize Up to and including 4.5.0
Timeline
- 2026-04-10: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/wp-optimize/tags/4.4.1/includes/class-wp-optimize-heartbeat.php
- https://plugins.trac.wordpress.org/browser/wp-optimize/tags/4.4.1/includes/class-wp-optimize-heartbeat.php
- https://plugins.trac.wordpress.org/browser/wp-optimize/trunk/includes/class-wp-optimize-heartbeat.php
- https://research.cleantalk.org/cve-2026-2712/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6a0a376e-ea3a-40ca-9341-f28f92e15e02?source=cve