Keeping your WordPress website running smoothly and securely is a constant effort. Sometimes, even trusted tools can have unexpected weaknesses. This post discusses a recently identified vulnerability in the RapidLoad Power-Up for Autoptimize plugin, a popular tool for enhancing website performance.
This particular flaw, identified as CVE-2023-1333, could allow an unauthorized user to cause disruption by clearing your website’s cache. While this doesn’t directly expose sensitive user data, it can impact website performance and user experience by forcing the site to rebuild its cached content, potentially slowing things down temporarily.
CVE Details
The RapidLoad Power-Up for Autoptimize plugin for WordPress contained a vulnerability due to a missing capability check. This allowed authenticated users, even those with basic subscriber-level access, to utilize the plugin’s clear_page_cache function. Essentially, the plugin didn’t properly verify if a user had the necessary permissions before allowing them to delete the website’s cache.
- Product: RapidLoad Power-Up for Autoptimize plugin for WordPress
- Published: March 10, 2023
- Severity: Medium
- Status: Analyzed
Affected Products
This vulnerability impacts versions of the RapidLoad Power-Up for Autoptimize plugin for WordPress up to, and including, 1.7.1. If you are running any version within this range, your website may be at risk.
Current Status
As of February 13, 2026, this vulnerability has been analyzed. This means the details of the flaw are understood and publicly available, allowing developers and users to take appropriate action.
Severity Level
The vulnerability holds a Medium severity rating. While an attacker can cause an unauthorized loss of cached data, leading to performance issues, it does not typically grant access to sensitive information or allow for full control over your website. However, any disruption to your website’s functionality can be problematic and should be addressed promptly.
Possible Solutions
The most crucial step to protect your WordPress site from CVE-2023-1333 is to update your RapidLoad Power-Up for Autoptimize plugin immediately. Ensure you update to a version greater than 1.7.1. Plugin developers typically release patches promptly once vulnerabilities are discovered, and keeping your software up-to-date is a fundamental cybersecurity best practice.
Before performing any updates, it’s always a good idea to back up your website. This ensures that in the unlikely event of an issue during the update process, you can easily restore your site.
References
https://plugins.trac.wordpress.org/changeset/2877726/unusedcss/trunk/includes/modules/unused-css/UnusedCSS_Admin.php?contextall=1&old=2847136&old_path=%2Funusedcss%2Ftrunk%2Fincludes%2Fmodules%2Funused-css%2FUnusedCSS_Admin.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/2cba74f7-7183-4297-8f04-4818c01358ef


