A security flaw has been found in the RapidLoad Power-Up for Autoptimize plugin, a popular tool for speeding up WordPress websites. This vulnerability, identified as CVE-2023-1334, could allow someone with low-level access to your site to mess with your website’s cached content. This means even a regular subscriber could potentially cause your site to display incorrect information or slow down its performance.
The problem stems from a missing security check within the plugin’s `queue_posts` function. Without this check, the plugin doesn’t properly confirm if a user has the necessary permissions to modify the cache, opening the door for unauthorized changes.
CVE Details
- Product: RapidLoad Power-Up for Autoptimize plugin for WordPress
- Published: March 10, 2023
- Severity: Medium
- Status: Analyzed
Affected Products
The vulnerability impacts all versions of the RapidLoad Power-Up for Autoptimize plugin for WordPress up to, and including, 1.7.1. If you are running any version within this range, your website could be at risk.
Current Status
This vulnerability has been thoroughly analyzed, and the good news is that a fix has been released. It is crucial for website administrators and developers to take action and update their installations to ensure their sites are protected.
Severity Level
Rated as Medium severity, this vulnerability is not as critical as those allowing full site takeover, but it still poses a significant risk. The fact that it requires an authenticated user (even a subscriber) means an attacker would need some level of access to your WordPress site. However, the ability to modify cache can lead to website defacement, disruption of service, or displaying outdated/incorrect content, which can negatively impact user experience and site reputation.
Possible Solutions
The most important step to secure your website against CVE-2023-1334 is to update your RapidLoad Power-Up for Autoptimize plugin immediately. Ensure you update to version 1.7.2 or higher. These updated versions include the necessary security checks to prevent unauthorized cache modifications.
Always remember to back up your website before performing any updates to plugins or themes. This ensures you can easily restore your site if any unexpected issues arise.
References
https://plugins.trac.wordpress.org/changeset/2877726/unusedcss/trunk/includes/modules/unused-css/UnusedCSS_Admin.php?contextall=1&old=2847136&old_path=%2Funusedcss%2Ftrunk%2Fincludes%2Fmodules%2Funused-css%2FUnusedCSS_Admin.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/f3108ef4-f889-4ae1-b86f-cedf46dcea19


