Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

BerqWP — Vulnerabilities & Security Advisories 4

Browse all 4 CVE security advisories affecting BerqWP. AI-powered Chinese analysis, POCs, and references for each vulnerability.

BerqWP is a WordPress performance optimization plugin designed to enhance website speed and user experience through caching and asset optimization. Historically, it has been associated with multiple security vulnerabilities including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, primarily stemming from insufficient input validation and improper access controls. The plugin has faced four publicly disclosed CVEs, with some instances allowing attackers to execute arbitrary code or compromise user accounts through manipulated parameters. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities suggests a need for rigorous security testing and input sanitization practices in future development cycles.

CVE IDTitleCVSSSeverityPublished
CVE-2025-58979 WordPress BerqWP Plugin <= 2.2.53 - Broken Access Control Vulnerability — BerqWPCWE-862 5.3 Medium2025-09-09
CVE-2025-7443 BerqWP <= 2.2.42 - Unauthenticated Arbitrary File Upload — BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScriptCWE-434 8.1 High2025-08-01
CVE-2024-9344 BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript <= 2.1.1 - Reflected Cross-Site Scripting — BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScriptCWE-79 6.1 Medium2024-10-02
CVE-2024-43160 WordPress BerqWP plugin <= 1.7.6 - Unauthenticated Arbitrary File Upload vulnerability — BerqWPCWE-434 10.0 Critical2024-08-13

This page lists every published CVE security advisory associated with BerqWP. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.