CVE-2026-7252

HIGH

The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid...

Affects 0 products across 5 vendors.

BCS5.82
CVSS 3.18.1
EPSS0.9%
Percentile58th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, no confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-22: Path Traversal

Attacker manipulates file path inputs to access files outside the intended directory.

Related Attack Patterns (CAPEC)
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
via CWE-22
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-22
CAPEC-78 Using Escaped Slashes in Alternate Encoding
via CWE-22
CAPEC-79 Using Slashes in Alternate Encoding
via CWE-22
CAPEC-126 Path Traversal
via CWE-22

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The WP-Optimize plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation, allowing authenticated attackers with author-level access and above to delete arbitrary files on the server.

BSID: BS-2026-GLOBAL-270485-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-7252?
The WP-Optimize plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation, allowing authenticated attackers with author-level access and above to delete arbitrary files on the server.
What is the CVSS score for CVE-2026-7252?
CVE-2026-7252 has CVSS 8.1 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H. EPSS: 0.9%.
Is CVE-2026-7252 actively exploited?
No confirmed active exploitation of CVE-2026-7252 as of 2026-05-30.
How do I remediate CVE-2026-7252?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-7252?
CVE-2026-7252 affects: Boost, Files, Form, Plugin, Wordpress.
Vulnerability Details
CVE IDCVE-2026-7252
BSIDBS-2026-GLOBAL-270485-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Published2026-05-07
Last Modified2026-05-07
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4.5.2 This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is possible because 'original-file' is a public (non-protected) meta key — it does not begin with an underscore — allowing Authors to freely create or modify it on their own attachment posts via the standard Edit Media form or the REST API.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability lies in the unscheduled_original_file_deletion function, which does not properly validate file paths before attempting to delete files. An attacker with the necessary permissions can exploit this to delete any file on the server by specifying a malicious file path.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Boost —
Files —
Form —
Plugin —
Wordpress —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 79 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash368012bbdcf3405c290849502ab0d2de9eb73e33bd7daa5eea2421bed9e17a9261fba93c11805acf19b645ef126982303f74446d348329f7748782e1690a1a9d
Related CVEs affecting Boost
CVE-2024-31682 9.8 Incorrect access control in the fingerprint authentication mechanism of Phone... CVE-2024-45489 9.8 Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boos... CVE-2026-7637 9.8 The Boost plugin for WordPress is vulnerable to PHP Object Injection in versi... CVE-2016-9840 8.8 Siemens CADRA CVE-2023-38297 8.4 An issue was discovered in a third-party com.factory.mmigroup component, ship...
View all Boost CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →