๐Ÿ” CVE Alert

CVE-2026-84934

HIGH 8.0

JCH Optimize < 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task Override

CVSS Score
8.0
EPSS Score
0.0%
EPSS Percentile
0th

The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site.

Vendor unknown
Product jch optimize
Published Sep 5, 2026
Last Updated Sep 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown jch optimize

Be the first to know when new high vulnerabilities affecting unknown jch optimize are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / JCH Optimize
0 < 6.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/d808ad17-d20e-4ee5-94f3-935c10cde772/

Credits

Artus KG WPScan