CVE-2026-84934

JCH Optimize · JCH Optimize WordPress Plugin

A stored cross-site scripting (XSS) vulnerability in the JCH Optimize WordPress plugin allows authenticated users to execute arbitrary scripts in the browsers of site visitors or administrators.

Executive summary

A stored cross-site scripting vulnerability in the JCH Optimize WordPress plugin allows authenticated users to execute malicious scripts, posing a significant risk of administrative account compromise.

Vulnerability

The plugin fails to perform a capability check on an authenticated AJAX action, enabling authenticated users to import arbitrary settings. This flaw allows an attacker to inject and store malicious scripts that execute in the browser of any user, including administrators, who views the affected site.

Business impact

Successful exploitation allows an attacker to execute scripts in the context of other users, which can lead to session hijacking, unauthorized actions performed on behalf of administrators, and potential full site takeover. Given the CVSS score of 8.0, this high severity vulnerability necessitates immediate attention to prevent unauthorized administrative access and potential data exfiltration.

Remediation

Immediate Action: Update the JCH Optimize WordPress plugin to version 6.0.1 or later.

Proactive Monitoring: Monitor WordPress audit logs for unusual AJAX activity or unauthorized configuration changes performed by low-privileged user accounts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block malicious script injection and restrict access to administrative AJAX endpoints.

Exploitation status

Public Exploit Available: No (Exploit_available: false)

Analyst recommendation

The vulnerability presents a high risk to the integrity and security of the WordPress environment. Administrators should prioritize updating the JCH Optimize plugin to version 6.0.1 immediately to eliminate the risk of stored XSS attacks.

History

CVE Brief tracked this CVE 5 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.0 (3.1)
  4. Analyst report written
  5. Analyst report updated

Sources

Originally found and disclosed by Artus KG, with WPScan (coordinator), per the CVE Program record.