๐Ÿ” CVE Alert

CVE-2025-15693

LOW 2.7

JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal

CVSS Score
2.7
EPSS Score
0.0%
EPSS Percentile
0th

The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root.

Vendor unknown
Product jch optimize
Published Sep 5, 2026
Last Updated Sep 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown jch optimize

Be the first to know when new low vulnerabilities affecting unknown jch optimize are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / JCH Optimize
4.2.1 < 5.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/73e664a8-9075-4fe6-9af4-b6f5d2ccfe3c/

Credits

Krugov Artyom WPScan