CVE-2026-16042
N/A
N/A
Summary
The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | LWS Optimize | 0 < 3.4 | affected |
Weaknesses
- CWE-862 Missing Authorization
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.