Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16
Critical0
High0
Medium16
Reset
Showing 1-16 of 16 records
Threat Entry Updated 2025-02-21

CVE-2024-13651 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_deactivate() function in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset some of the plugin's settings.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2024-13651

MEDIUM CVSS 4.3 2025-02-01
Threat Entry Updated 2024-11-21

CVE-2023-1472 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they can trick a site administrator into performing an action such as clicking on a link. Actions include resetting the API key, accessing or deleting log files, and deleting cache among others.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1472

MEDIUM CVSS 6.3 2023-03-17
Threat Entry Updated 2026-02-13

CVE-2023-1346 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_page_cache function. This makes it possible for unauthenticated attackers to clear the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1346

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1345 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the queue_posts function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1345

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1344 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the uucss_update_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1344

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1343 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the attach_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1343

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1342 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ucss_connect function. This makes it possible for unauthenticated attackers to connect the site to a new license key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1342

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1341 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate function. This makes it possible for unauthenticated attackers to turn off caching via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1341

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1340 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_uucss_logs function. This makes it possible for unauthenticated attackers to clear plugin logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1340

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1339 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the uucss_update_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to update caching rules.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1339

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1338 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the attach_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify cache rules.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1338

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1337 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete plugin log files.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1337

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1336 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the ajax_deactivate function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to disable caching.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1336

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1335 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the ucss_connect function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to connect a new license key to the site.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1335

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1334 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the queue_posts function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify the plugin's cache.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1334

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-13

CVE-2023-1333 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_page_cache function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete the plugin's cache.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1333

MEDIUM CVSS 4.3 2023-03-10
Scroll to top