Access violation vulnerability in NGINX Cache Optimizer 1.1

The NGINX Cache Optimizer plugin for WordPress has a security issue that allows unauthorized changes to be made to the data. This is because there is no check in place to ensure that only authorized users can access the ‘nginxcacheoptimizer-blacklist-update’ feature. This means that anyone with Subscriber-level access or higher can add URLs to the Exclude URLs From Dynamic Caching setting.

Detected in:

NGINX Cache Optimizer open vulnerable versions: >= * <= 1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.