NitroPack <= 1.19.3 - Missing Authorization
medium
The NitroPack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.19.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.19.3
- Fixed in:
- 1.19.4
- Disclosed:
- Feb 18, 2026
CVE-2026-39669 on NVD →
NitroPack <= 1.18.4 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update via nitropack_set_compression_ajax Function
medium
The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the nitropack_set_compression_ajax() function in all versions up to, and including, 1.18.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the...
- CVSS:
- 4.3
- Affected:
- up to 1.18.4
- Fixed in:
- 1.18.5
- Disclosed:
- Sep 9, 2025
CVE-2025-8778 on NVD →
NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN [nitropack] < 1.17.6
unknown
[en] The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the nitropack_rml_notification function in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber access or higher, to update arbi...
- Affected:
- up to 1.17.6
- Fixed in:
- 1.17.6
- Disclosed:
- Jan 15, 2025
CVE-2024-11851 on NVD →
NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN [nitropack] < 1.17.6
unknown
[en] The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to...
- Affected:
- up to 1.17.6
- Fixed in:
- 1.17.6
- Disclosed:
- Jan 15, 2025
CVE-2024-11848 on NVD →
NitroPack <= 1.17.0 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update
high
The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to updat...
- CVSS:
- 8.1
- Affected:
- up to 1.17.0
- Fixed in:
- 1.17.6
- Disclosed:
- Jan 14, 2025
CVE-2024-11848 on NVD →
NitroPack <= 1.17.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Transient Update
medium
The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the nitropack_rml_notification function in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber access or higher, to update arbitrary...
- CVSS:
- 4.3
- Affected:
- up to 1.17.0
- Fixed in:
- 1.17.6
- Disclosed:
- Jan 14, 2025
CVE-2024-11851 on NVD →
NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN [nitropack] < 1.16.8
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7.
- Affected:
- up to 1.16.8
- Fixed in:
- 1.16.8
- Disclosed:
- Aug 29, 2024
CVE-2024-43922 on NVD →
NitroPack <= 1.16.7 - Unauthenticated Arbitrary Shortcode Execution
high
The The NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.16.7. This is due to the software allowing users to execute an action that does not properly validate...
- CVSS:
- 7.3
- Affected:
- up to 1.16.7
- Fixed in:
- 1.16.8
- Disclosed:
- Aug 26, 2024
CVE-2024-43922 on NVD →
NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN [nitropack] < 1.10.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in NitroPack Inc. NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images.This issue affects NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images: from n/a through 1.10.2.
- Affected:
- up to 1.10.3
- Fixed in:
- 1.10.3
- Disclosed:
- Jan 5, 2024
CVE-2023-52121 on NVD →
NitroPack <= 1.10.2 - Cross-Site Request Forgery
medium
The NitroPack plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.2. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke them via a forged request granted they can trick a site admin...
- CVSS:
- 4.3
- Affected:
- up to 1.10.2
- Fixed in:
- 1.10.3
- Disclosed:
- Dec 28, 2023
CVE-2023-52121 on NVD →
NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN [nitropack] < 1.10.0
unknown
- Affected:
- up to 1.10.0
- Fixed in:
- 1.10.0
- Disclosed:
- Nov 13, 2023
CVE-2023-6034 on NVD →
NitroPack <= 1.9.2 - Missing Authorization via multiple AJAX functions
medium
The NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX function in all versions up to, and including, 1.9.2. This...
- CVSS:
- 6.3
- Affected:
- up to 1.10.0
- Fixed in:
- 1.10.0
- Disclosed:
- Nov 7, 2023
NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN [nitropack] < 1.10.0
unknown
The plugin is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX function in all versions up to, and including, 1.9.2. This makes it possible for authenticated attackers, with subscriber access and above, to perform actions such as cleari...
- Affected:
- up to 1.10.0
- Fixed in:
- 1.10.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database