CVE-2025-15693 PUBLISHED

JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal

Assigner: WPScan
Reserved: 02.09.2026 Published: 05.09.2026 Updated: 05.09.2026

The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root.

Product Status

Vendor Unknown
Product JCH Optimize
Versions Default: unaffected
  • affected from 4.2.1 to 5.0.1 (excl.)

Credits

  • Krugov Artyom finder
  • WPScan coordinator

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE