CVE-2024-13651
- EPSS 0.1%
- Veröffentlicht 01.02.2025 04:15:30
- Zuletzt bearbeitet 21.02.2025 15:55:18
The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_deactivate() function in all versions up to, and including, 2.4.4. This makes it p...
CVE-2024-31288
- EPSS 0.13%
- Veröffentlicht 07.04.2024 18:15:11
- Zuletzt bearbeitet 21.11.2024 09:13:12
Server-Side Request Forgery (SSRF) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize.This issue affects RapidLoad Power-Up for Autoptimize: from n/a through 2.2.11.
CVE-2022-47593
- EPSS 0.21%
- Veröffentlicht 22.06.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:32:13
Auth. (subscriber+) SQL Injection (SQLi) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize plugin <= 1.6.35 versions.
CVE-2023-1472
- EPSS 0.07%
- Veröffentlicht 17.03.2023 15:15:11
- Zuletzt bearbeitet 21.11.2024 07:39:15
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unau...
CVE-2023-1346
- EPSS 0.07%
- Veröffentlicht 10.03.2023 20:15:11
- Zuletzt bearbeitet 13.02.2026 21:44:25
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_page_cache function. This makes it poss...
CVE-2023-1345
- EPSS 0.07%
- Veröffentlicht 10.03.2023 20:15:11
- Zuletzt bearbeitet 20.02.2026 21:24:01
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the queue_posts function. This makes it possible ...
CVE-2023-1344
- EPSS 0.07%
- Veröffentlicht 10.03.2023 20:15:11
- Zuletzt bearbeitet 20.02.2026 20:39:22
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the uucss_update_rule function. This makes it pos...
CVE-2023-1342
- EPSS 0.07%
- Veröffentlicht 10.03.2023 20:15:10
- Zuletzt bearbeitet 20.02.2026 20:38:32
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ucss_connect function. This makes it possible...
CVE-2023-1343
- EPSS 0.07%
- Veröffentlicht 10.03.2023 20:15:10
- Zuletzt bearbeitet 20.02.2026 20:38:50
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the attach_rule function. This makes it possible ...
CVE-2023-1333
- EPSS 0.09%
- Veröffentlicht 10.03.2023 20:15:10
- Zuletzt bearbeitet 13.02.2026 21:44:17
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_page_cache function in versions up to, and including, 1.7.1. This makes it possible for authenticate...