VYPR

Wp Optimizer

by WordPress

Source repositories

CVEs (2)

  • CVE-2025-53314CriJun 27, 2025
    risk 0.62cvss 9.6epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer wp-optimizer allows SQL Injection.This issue affects WP Optimizer: from n/a through <= 2.5.0.

  • CVE-2026-6295MedSep 19, 2026
    risk 0.25cvss 4.9epss 0.01

    The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is due to an unsafe subquery-detection branch in the Query::parse_key_compare_field() method that, when the user-supplied value matches the…