RapidLoad Power-Up for Autoptimize Cross-Site Request Forgery Vulnerability (CVE-2023-1344) — Medium Severity

A security flaw has been found in the RapidLoad Power-Up for Autoptimize plugin for WordPress, specifically identified as CVE-2023-1344. This vulnerability could allow attackers to manipulate your website’s cache without needing to log in, simply by tricking an administrator into clicking a malicious link. This type of attack is known as Cross-Site Request Forgery (CSRF).

CVE Details

  • Product: RapidLoad Power-Up for Autoptimize plugin for WordPress
  • Published: March 10, 2023
  • Severity: Medium
  • Status: Analyzed

Affected Products

The vulnerability impacts versions of the RapidLoad Power-Up for Autoptimize plugin for WordPress up to, and including, version 1.7.1.

Current Status

The vulnerability has been thoroughly analyzed, meaning its nature and impact are well-understood by security researchers and the vendor. This status indicates that a fix or mitigation strategy should be available.

Severity Level

With a CVSS score of 4.3, this vulnerability is rated as Medium severity. While not critical, a successful CSRF attack can still cause significant disruption. An attacker could potentially alter your website’s caching behavior, leading to unexpected performance issues, incorrect content display, or even more serious problems if the cached data is manipulated to serve malicious content to your visitors.

Possible Solutions

The good news is that a fix for this vulnerability has been released. To protect your WordPress site, it is crucial to update your RapidLoad Power-Up for Autoptimize plugin to version 1.7.2 or later as soon as possible. This update introduces proper nonce validation to the `uucss_update_rule` function and other relevant areas, which is a security token used to prevent CSRF attacks. Nonce validation ensures that requests made to your website are legitimate and originate from your own site, not from an attacker’s forged request.

Always keep your WordPress core, themes, and plugins updated to their latest versions to benefit from the most recent security patches.

References

https://plugins.trac.wordpress.org/changeset/2877726/unusedcss/trunk/includes/modules/unused-css/UnusedCSS_Admin.php?contextall=1&old=2847136&old_path=%2Funusedcss%2Ftrunk%2Fincludes%2Fmodules%2Funused-css%2FUnusedCSS_Admin.php

https://www.wordfence.com/threat-intel/vulnerabilities/id/263153c9-61c5-4df4-803b-8d274e2a5e35

https://plugins.trac.wordpress.org/changeset/2877726/unusedcss/trunk/includes/modules/unused-css/UnusedCSS_Admin.php?contextall=1&old=2847136&old_path=%2Funusedcss%2Ftrunk%2Fincludes%2Fmodules%2Funused-css%2FUnusedCSS_Admin.php

https://www.wordfence.com/threat-intel/vulnerabilities/id/263153c9-61c5-4df4-803b-8d274e2a5e35

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.