Executive brief
Falcon is a WordPress plugin used to optimize website performance and speed. A security vulnerability in versions 2.10.0 and earlier could allow an unauthenticated attacker to disrupt the website's availability. This could lead to service outages or significant performance degradation, potentially impacting user experience and business operations.
Technical details
The Falcon – WordPress Optimizations & Tweaks plugin for WordPress (versions up to and including 2.10.0) is vulnerable to a high-severity issue classified as Improper Validation of Specified Quantity (CWE-1284). An unauthenticated remote attacker can exploit this flaw over the network without any user interaction. Based on the CVSS vector, the primary impact is on system availability, suggesting the vulnerability can be used to trigger a denial-of-service (DoS) condition. The issue is addressed in version 2.10.1.
Affected products
- Anh Tran (eLightUp) Falcon – WordPress Optimizations & Tweaks <= 2.10.0
Timeline
- 2026-04-30: other: Reported by researcher dodoh4t
- 2026-07-23: advisory: Patchstack advisory published
- 2026-07-27: disclosed: CVE published to NVD
- 2026-07-27: patched: Patch available in version 2.10.1