Extension WordPress
Vulnérabilités NitroPack – Performance, Page Speed & Cache Plugin for Core Web Vitals, CDN & Image Optimization
Cette page rassemble les failles publiées pour NitroPack – Performance, Page Speed & Cache Plugin for Core Web Vitals, CDN & Image Optimization, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de NitroPack – Performance, Page Speed & Cache Plugin for Core Web Vitals, CDN & Image Optimization
7 fiches
NitroPack <= 1.19.3 – Missing Authorization
The NitroPack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.19.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
*-1.19.3
1.19.4
18/02/2026
NitroPack <= 1.18.4 – Missing Authorization to Authenticated (Subscriber+) Limited Settings Update via nitropack_set_compression_ajax Function
The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the nitropack_set_compression_ajax() function in all versions up to, and including, 1.18.4. This makes it possible for authenticated attackers, with…
*-1.18.4
1.18.5
09/09/2025
NitroPack <= 1.17.0 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Transient Update
The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the nitropack_rml_notification function in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with…
*-1.17.0
1.17.6
14/01/2025
NitroPack <= 1.17.0 – Missing Authorization to Authenticated (Subscriber+) Limited Options Update
The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers,…
*-1.17.0
1.17.6
14/01/2025
NitroPack <= 1.16.7 – Unauthenticated Arbitrary Shortcode Execution
The The NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.16.7.…
*-1.16.7
1.16.8
26/08/2024
NitroPack <= 1.10.2 – Cross-Site Request Forgery
The NitroPack plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.2. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to…
*-1.10.2
1.10.3
28/12/2023
NitroPack <= 1.9.2 – Missing Authorization via multiple AJAX functions
The NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a…
[*, 1.10.0)
1.10.0
07/11/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.