Rapidload is a performance-optimization plugin for WordPress that operates within the WordPress ecosystem, with its vulnerability footprint centered on the Power-Up for Autoptimize product. The recurring exposure reflects characteristic web-application weaknesses: cross-site request forgery, missing authorization checks, and SQL injection, alongside insufficient threat data, indicating the typical attack surface of a server-side WordPress plugin handling user input and administrative functions. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rapidload over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1472MEDIUM The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect | Mar 17, 2023 | 6.3 | 22 | NO | NO |
CVE-2024-31288HIGH Server-Side Request Forgery (SSRF) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize.This issue affects RapidLoad Power-Up for Autoptimize: from n/a through 2.2.11. | Apr 7, 2024 | 7.2 | 20 | NO | NO |
CVE-2022-47593MEDIUM Auth. (subscriber+) SQL Injection (SQLi) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize plugin <= 1.6.35 versions. | Jun 22, 2023 | 6.5 | 18 | NO | NO |
CVE-2023-1345MEDIUM The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect | Mar 10, 2023 | 4.3 | 18 | NO | NO |
CVE-2023-1337MEDIUM The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions u | Mar 10, 2023 | 4.3 | 18 | NO | NO |
CVE-2023-1346MEDIUM The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect | Mar 10, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-1344MEDIUM The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect | Mar 10, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-1343MEDIUM The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect | Mar 10, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-1342MEDIUM The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect | Mar 10, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-1341MEDIUM The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect | Mar 10, 2023 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rapidload.
Media articles that mention a CVE ID that affects a product developed by Rapidload — matched by CVE ID, not by vendor name.