CyberRota Analysis
AI-GeneratedThe JCH Optimize plugin for WordPress versions prior to 5.0.1 is vulnerable due to inadequate restrictions on directory paths in its administrative image-browsing feature, enabling high-privilege users to access and enumerate files and directories beyond the intended web root. This could lead to unauthorized exposure of sensitive files, posing a significant risk to site security. WordPress administrators, particularly those managing multisite environments, should prioritize updating to the latest version to mitigate this vulnerability.
Original NVD Description
The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root.