Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

optimole — Vulnerabilities & Security Advisories 8

Browse all 8 CVE security advisories affecting optimole. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Optimole provides website optimization services, focusing on image and video delivery to improve site performance. Historically, the platform has been associated with cross-site scripting (XSS) and remote code execution vulnerabilities, with six CVEs recorded to date. These issues often stem from improper input validation and insufficient access controls in its optimization features. While no major public security incidents have been widely documented, the consistent presence of XSS and RCE vulnerabilities in its history suggests potential risks for implementations lacking proper hardening or timely updates. Organizations deploying Optimole should prioritize applying security patches and implementing additional input sanitization measures to mitigate these recurring vulnerability classes.

CVE IDTitleCVSSSeverityPublished
CVE-2026-57673 WordPress Optimole plugin <= 4.2.7 - Cross Site Scripting (XSS) vulnerability — OptimoleCWE-79 7.1 High2026-07-02
CVE-2026-11784 Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX Action — Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image OptimizationCWE-352 4.3 Medium2026-06-18
CVE-2026-5217 Optimole <= 4.2.2 - Unauthenticated Stored Cross-Site Scripting via Srcset Descriptor Parameter — Optimole – Optimize Images in Real TimeCWE-79 7.2 High2026-04-11
CVE-2026-5226 Optimole <= 4.2.3 - Reflected Cross-Site Scripting via Page Profiler URL — Optimole – Optimize Images in Real TimeCWE-79 6.1 Medium2026-04-11
CVE-2026-1843 Super Page Cache <= 5.2.2 - Unauthenticated Stored Cross-Site Scripting via Activity Log — Super Page CacheCWE-79 7.2 High2026-02-14
CVE-2025-11519 Image optimization service by Optimole <= 4.1.0 - Insecure Direct Object Reference to Authenticated (Author+) Media Offload — Optimole – Optimize Images in Real TimeCWE-639 4.3 Medium2025-10-18
CVE-2024-4636 Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF <= 3.12.10 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload — Optimole – Optimize Images in Real TimeCWE-79 6.4 Medium2024-05-15
CVE-2024-27968 WordPress Super Page Cache for Cloudflare plugin <= 4.7.5 - Cross Site Request Forgery (CSRF) to XSS vulnerability — Super Page Cache for CloudflareCWE-352 7.1 High2024-03-21

This page lists every published CVE security advisory associated with optimole. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.