CVE · Critical

CVE-2019-25217 — Speed Optimizer – The All-In-One Performance-Boosting Plugin [sg-cachepress] < 5.0.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-25217 Speed Optimizer – The All-In-One Performance-Boosting Plugin [sg-cachepress] < 5.0.13 Missing Authorization Critical 9.8 < 5.0.13 5.0.13 2019-03-14

CVE-2019-25217

The SiteGround Optimizer plugin through version 5.0.12 contains an authorization bypass vulnerability in its /switch-php REST API endpoint that fails to properly validate access permissions on the switch_php function. This flaw allows unauthenticated attackers to include and execute arbitrary files from the server, enabling them to run malicious PHP code and potentially compromise the entire WordPress installation. The vulnerability can be exploited to bypass security restrictions, steal sensitive information, or execute code through uploaded files that would normally be considered safe, such as images.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.