SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2025-15693

LOW · CVSS 2.7 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The JCH Optimize plugin for WordPress versions prior to 5.0.1 is vulnerable due to inadequate restrictions on directory paths in its administrative image-browsing feature, enabling high-privilege users to access and enumerate files and directories beyond the intended web root. This could lead to unauthorized exposure of sensitive files, posing a significant risk to site security. WordPress administrators, particularly those managing multisite environments, should prioritize updating to the latest version to mitigate this vulnerability.

CVE
CVE-2025-15693
Severity
LOW
CVSS
2.7
EPSS
0.27%
WordPress

Original NVD Description

The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root.