Executive brief
NitroPack is a popular WordPress plugin used to optimize website speed and performance. A security flaw in the plugin's access control settings could allow unauthorized individuals to bypass intended security levels, potentially leading to the exposure of internal configuration details or restricted information. While the impact is considered moderate, it could be used as a stepping stone for further attacks on the website.
Technical details
A missing authorization (CWE-862) vulnerability exists in the NitroPack plugin for WordPress in versions up to and including 1.19.3. The flaw stems from insufficient validation of access control security levels, which can be exploited by a remote, unauthenticated attacker. By sending specially crafted requests, an attacker can bypass intended restrictions to access functionality or information that should be protected. This issue was addressed in version 1.19.4 by implementing proper authorization checks.
Affected products
- NitroPack NitroPack through 1.19.3
Timeline
- 2026-01-19: other: Vulnerability reported by Steven Julian
- 2026-02-18: disclosed: Vulnerability details published by Patchstack
- 2026-04-08: advisory: CVE published to NVD
- 1.19.4: patched: Vulnerability fixed in version 1.19.4