CVE-2026-7252
The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid...
Affects 0 products across 5 vendors.
Attacker manipulates file path inputs to access files outside the intended directory.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
The WP-Optimize plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation, allowing authenticated attackers with author-level access and above to delete arbitrary files on the server.
BSID: BS-2026-GLOBAL-270485-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-7252?
What is the CVSS score for CVE-2026-7252?
Is CVE-2026-7252 actively exploited?
How do I remediate CVE-2026-7252?
What systems are affected by CVE-2026-7252?
| CVE ID | CVE-2026-7252 |
|---|---|
| BSID | BS-2026-GLOBAL-270485-H BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| Published | 2026-05-07 |
| Last Modified | 2026-05-07 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4.5.2 This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is possible because 'original-file' is a public (non-protected) meta key — it does not begin with an underscore — allowing Authors to freely create or modify it on their own attachment posts via the standard Edit Media form or the REST API.
Source: NIST NVD / MITRE CVE Database
The vulnerability lies in the unscheduled_original_file_deletion function, which does not properly validate file paths before attempting to delete files. An attacker with the necessary permissions can exploit this to delete any file on the server by specifying a malicious file path.
Exploitation Likelihood: HIGH
| Vendor | Product | Fixed Version |
|---|---|---|
| Boost | — | — |
| Files | — | — |
| Form | — | — |
| Plugin | — | — |
| Wordpress | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 368012bbdcf3405c290849502ab0d2de9eb73e33bd7daa5eea2421bed9e17a9261fba93c11805acf19b645ef126982303f74446d348329f7748782e1690a1a9d |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →