plugin

Wp2Speed Vulnerabilities

4 known security issues reported for the Wp2Speed WordPress plugin. Most recent disclosed Aug 12, 2024.

2 medium

Running Wp2Speed on your site? Check whether your installed version is affected.

Scan your site free

WP2Speed Faster &#8211; Optimize PageSpeed Insights Score 90-100 [wp2speed] <= 1.0.1 (unfixed + closed)

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wp2speed WP2Speed Faster allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP2Speed Faster: from n/a through 1.0.1.

Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Aug 12, 2024

CVE-2024-37924 on NVD →

WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 <= 1.0.1 - Unauthenticated Information Exposure

medium

The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to extract potentially sensitive information.

CVSS:
5.3
Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Jul 9, 2024

CVE-2024-37924 on NVD →

WP2Speed Faster &#8211; Optimize PageSpeed Insights Score 90-100 [wp2speed] <= 1.0.1 (unfixed + closed)

unknown

[en] The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers t...

Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Jul 9, 2024

CVE-2024-5810 on NVD →

WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 <= 1.0.1 - Improper Authorization due to use of Hardcoded Credentials

medium

The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers to ove...

CVSS:
5.3
Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Jul 8, 2024

CVE-2024-5810 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database