Medium severity4.3NVD Advisory· Published Feb 1, 2025· Updated Jun 17, 2026
CVE-2024-13651
CVE-2024-13651
Description
The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_deactivate() function in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset some of the plugin's settings.
Affected products
4- cpe:2.3:a:rapidload:rapidload_power-up_for_autoptimize:*:*:*:*:*:wordpress:*:*Range: <2.4.5
- Range: <=2.4.4
- shakee93/RapidLoad AI – Optimize Web Vitals Automaticallyv5Range: 0
Patches
Vulnerability mechanics
References
2- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/87f9f052-2963-4548-9ff8-91dc2b4ecb43nvdThird Party Advisory
News mentions
0No linked articles in our index yet.