Access violation vulnerability in NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images 1.10.0

The NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images plugin for WordPress is not secure. A flaw in the plugin code leaves it vulnerable to malicious attacks. Attackers who have even a basic user account on the website, such as a subscriber, can use this vulnerability to change data, delete data, or access data they should not have access to. The vulnerability affects all versions of the plugin up to version 1.9.2. Possible actions an attacker could take include deleting the website’s cache, dismissing important notifications, or enabling a ‘safe mode’ without permission.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.