CVE-2026-12089: WS Optimize – All-in-One Speed Booster & Cache Tools <= 3.3.19 - Authenticated (Editor+) Arbitrary File Read

Published Jun 13, 2026
·
Updated

The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.3.19. This is due to the combinecurrentcss() function trusting <link rel="stylesheet" href="..."> values harvested from page HTML and converting same-site URLs to absolute filesystem paths before reading them with filegetcontents()/Minify\CSS::add(), without enforcing that the resolved path stay within ABSPATH or have a .css extension. This makes it possible for authenticated attackers, with Editor-level access and above, to read arbitrary files.

Affected Software

1 affected component
LWS LWS Optimize – All-in-One Speed Booster & Cache Tools<=3.3.19

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove LWS Optimize – All-in-One Speed Booster & Cache Tools from your environment.

    Uninstall the affected plugin if it is not required to eliminate the vulnerable code path.

  2. Configuration

    Modify the plugin's combine_current_css() behaviour so that any same-site URLs resolved to filesystem paths are validated: ensure the resolved path remains inside ABSPATH (no directory traversal outside the webroot) and that the file has a .css extension before calling file_get_contents() or Minify\CSS::add(). Reject or skip any paths that fail validation.

    LWS Optimize – All-in-One Speed Booster & Cache Tools (combine_current_css) CSS path resolution validation = enforce resolved path within ABSPATH and require .css extension
  3. Configuration

    Disable the plugin's CSS combining/merging/optimization feature (the functionality that invokes combine_current_css()) in plugin settings to prevent processing of <link rel="stylesheet"> href values until a coded remediation is applied.

    LWS Optimize – All-in-One Speed Booster & Cache Tools CSS combine/merge feature = disabled
  4. Compensating control

    Limit and audit Editor-level and higher user accounts: restrict Editor+ privileges to trusted administrators, remove or reassign unnecessary Editor accounts, and enforce strong account hygiene to reduce risk from authenticated attackers.

  5. Operational

    Audit webserver and WordPress logs for suspicious file reads or unexpected access patterns involving the plugin; investigate any indications of exploitation and remediate exposed data or compromised sites.

Event History

Jun 13, 2026
CVE Published
via MITRE·02:29 AM
Data Sourced
via MITRE·02:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-12089?

The severity of CVE-2026-12089 is rated as medium with a score of 4.9.

2

How do I fix CVE-2026-12089?

To fix CVE-2026-12089, update the LWS Optimize – All-in-One Speed Booster & Cache Tools plugin to version 3.3.20 or later.

3

What type of vulnerability is CVE-2026-12089?

CVE-2026-12089 is a path traversal vulnerability allowing authenticated users to read arbitrary files.

4

Who is affected by CVE-2026-12089?

Any WordPress site using the LWS Optimize – All-in-One Speed Booster & Cache Tools plugin version 3.3.19 or earlier is affected by CVE-2026-12089.

5

What is the impact of CVE-2026-12089?

The impact of CVE-2026-12089 can lead to unauthorized file access and exposure of sensitive information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203