CVE-2026-12089

WS Optimize – All-in-One Speed Booster & Cache Tools <= 3.3.19 - Authenticated (Editor+) Arbitrary File Read

2026-06-12 14:06
Omar Elshopky (3l5h0pky)

Strategic Overview

Status
Patched in 3.3.20
Affected Version
<= 3.3.19
CVSS
4.9Medium
Weakness type
CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE
CVE-2026-12089
View all LWS Optimize – All-in-One Speed Booster & Cache Tools vulnerabilities

At a glance

CVE-2026-12089 is a medium-severity Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the LWS Optimize WordPress plugin, affecting versions <= 3.3.19. It carries a CVSS score of 4.9 (reachable over the network; low attack complexity; high confidentiality impact). Exploitation requires an authenticated account at Editor level or above. The issue is fixed in version 3.3.20; sites on affected versions should update now. Disclosed June 2026, reported by Omar Elshopky (3l5h0pky).

Vulnerability Overview

The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.3.19. This is due to the combine_current_css() function trusting <link rel="stylesheet" href="..."> values harvested from page HTML and converting same-site URLs to absolute filesystem paths before reading them with file_get_contents()/Minify\CSS::add(), without enforcing that the resolved path stay within ABSPATH or have a .css extension. This makes it possible for authenticated attackers, with Editor-level access and above, to read arbitrary files.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user. A successful exploit has high impact on confidentiality.

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

LWS Optimize <= 3.3.19 carries this weakness at stylesheet, and reaching it takes an account at Editor level or above. Path traversal happens when user-controlled text is used to build a filesystem path without being constrained to an intended directory, so sequences like ../ walk the resolved path somewhere else.

Depending on the operation, it means reading files outside the intended folder — wp-config.php being the usual target — or writing to and deleting paths the web server can touch. For LWS Optimize the fix is 3.3.20: builds <= 3.3.19 are affected, anything from 3.3.20 onward is not.

Remediation

Update to version 3.3.20, or a newer patched version

How does WordSec protect against this?

An attacker needs Editor access first, so the firewall sees the attempt as traffic from a logged-in account: WordSec's web application firewall inspects request payloads before WordPress loads them. None of that substitutes for the fix: LWS Optimize 3.3.20 closes this, and updating the plugin is the step that ends it.

  • Firewall
  • Alerts

External References

Related records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C