---
id: CVE-2026-84934
title: >-
  The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability
  check on one of its authenticated AJAX actions and lets the request choose
  which internal action runs, allowing any authenticated users such as
  Subscribers to i…
summary: >-
  The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability
  check on one of its authenticated AJAX actions and lets the request choose
  which internal action runs, allowing any authenticated users such as
  Subscribers to i…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
published: '2026-09-05'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:15:18.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84934'
references:
  - url: 'https://wpscan.com/vulnerability/d808ad17-d20e-4ee5-94f3-935c10cde772/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00413
epssPercentile: 0.32849
ingestedAt: '2026-09-06T11:54:30.344Z'
---

## Overview

The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
