CVE-2026-84934
JCH Optimize < 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task Override
CVSS Score
8.0
EPSS Score
0.0%
EPSS Percentile
0th
The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site.
| Vendor | unknown |
| Product | jch optimize |
| Published | Sep 5, 2026 |
| Last Updated | Sep 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown jch optimize
Be the first to know when new high vulnerabilities affecting unknown jch optimize are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / JCH Optimize
0 < 6.0.1
References
Credits
Artus KG WPScan