A security vulnerability has been identified in the RapidLoad Power-Up for Autoptimize plugin for WordPress. This flaw, tracked as CVE-2023-1342, could allow attackers to perform actions on a website without an administrator’s explicit consent. While categorized as a medium-severity issue, it’s important for site owners to understand the risk and take appropriate measures.
CVE Details
Product: RapidLoad Power-Up for Autoptimize plugin for WordPress
Published Date: March 10, 2023
Severity: Medium
Status: Analyzed
Affected Products
The vulnerability impacts the RapidLoad Power-Up for Autoptimize plugin for WordPress in versions up to, and including, 1.7.1. If you are using version 1.7.1 or older, your site is vulnerable.
Current Status
The vulnerability has been analyzed and a fix has been implemented in subsequent versions of the plugin. This means that an update is available to address the security flaw.
Severity Level
This vulnerability carries a Medium severity rating. It is a Cross-Site Request Forgery (CSRF) flaw, meaning an attacker could trick a logged-in administrator into clicking a malicious link. If successful, this could lead to the attacker being able to connect the site to a new license key via a forged request. While this doesn’t directly grant full control over the website, it could disrupt plugin functionality and potentially allow an attacker to gain unauthorized control over the plugin’s licensing on the affected site.
Possible Solutions
The good news is that a patch is available for this vulnerability. The fix involves implementing proper nonce validation in vulnerable functions like ucss_connect, which prevents unauthorized requests from being processed.
To protect your WordPress site, you should:
- Update Your Plugin: The most critical step is to update your RapidLoad Power-Up for Autoptimize plugin to version 1.7.2 or higher. Always ensure your plugins are up to date to receive the latest security fixes.
- Educate Users: Advise your site administrators and other privileged users to be cautious about clicking on suspicious links, especially those received via email or untrusted sources.
- Implement Security Best Practices: Regularly back up your website, use strong, unique passwords, and consider implementing a Web Application Firewall (WAF) for an additional layer of protection.
References
https://plugins.trac.wordpress.org/changeset/2877726/unusedcss/trunk/includes/modules/unused-css/UnusedCSS_Admin.php?contextall=1&old=2847136&old_path=%2Funusedcss%2Ftrunk%2Fincludes%2Fmodules%2Funused-css%2FUnusedCSS_Admin.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/7c66894a-8d0f-4946-ae4d-bffd35f3ffb7


