CVE-2026-2712Disclosure

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly invoking `Updraft_Smush_Manager_Commands` methods without verifying user capabilities, nonce tokens, or the allowed commands whitelist that the normal AJAX handler (`updraft_smush_ajax`) enforces. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke admin-only Smush operations including reading log files (`get_smush_logs`), deleting all backup images (`clean_all_backup_images`), triggering bulk image processing (`process_bulk_smush`), and modifying Smush options (`update_smush_options`).

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-04-10); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-19: 1Technical Details · 2026-04-10: 104-1004-1104-1904-20
Signal classification3 categories
Disclosure
250.0%
General
125.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-101
Disclosure1
2026-04-111
General1
2026-04-191
PoC1
2026-04-201
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2712 The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `in… https://www.cve.org/CVERecord?id=CVE-2026-2712

    Post summary

    The WP-Optimize plugin contains missing capability checks in its `receive_heartbeat()` function, enabling unauthorized access to functionality. The CVE is referenced via a cve.org link but no further details are given.

    00010136
    57.0K followersView on X
  • AdminGuide - Guide for IT Pro@AdmGuide
    Disclosure

    1M+ WordPress sitesini etkileyen WP-Optimize açığı! (CVE-2026-2712) ⚠️ Risk Seviyesi: YÜKSEK Teknik detaylar ve sistem yöneticisi tavsiyeleri için: 🔗 https://adminguide.info/wp-optimize-zafiyeti-1-milyon-wordpress-sitesi-risk-altinda-cve-2026-2712/ #WordPress #CyberAlert #ZeroDay https://t.co/slF2ROdsKR

    Post summary

    The tweet announces the discovery of a high‑risk CVE affecting over a million WordPress sites, linking to an external article for details.

    000004
    57 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-2712-wp-optimize-version-4-5-0-medium-vulnerability-proof-of-concept CVE-2026-2712 #WordPress plugin #vulnerability wp-optimize #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The link leads to a proof‑of‑concept for CVE‑2026‑2712 affecting the wp‑optimize WordPress plugin, with no evidence of active exploitation, patch, or detailed technical description.

    0000061
    6 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-2712 📊 Severity: 5.4 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2712 #CVE-2026-2712 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/ETdtmr6bMD

    Post summary

    A brief alert posts CVE‑2026‑2712 with its severity and affected Wordpress, but offers no further technical or actionable details.

    0000043
    123 followersView on X

Explore more