Junglewise Threat Intelligence

CVE-2026-59531: Anh Tran Falcon WordPress plugin denial of service

CVE-2026-59531 · Severity: high · CVSS 7.5 · Published 2026-07-27

Executive brief

Falcon is a WordPress plugin used to optimize website performance and speed. A security vulnerability in versions 2.10.0 and earlier could allow an unauthenticated attacker to disrupt the website's availability. This could lead to service outages or significant performance degradation, potentially impacting user experience and business operations.

Technical details

The Falcon – WordPress Optimizations & Tweaks plugin for WordPress (versions up to and including 2.10.0) is vulnerable to a high-severity issue classified as Improper Validation of Specified Quantity (CWE-1284). An unauthenticated remote attacker can exploit this flaw over the network without any user interaction. Based on the CVSS vector, the primary impact is on system availability, suggesting the vulnerability can be used to trigger a denial-of-service (DoS) condition. The issue is addressed in version 2.10.1.

Affected products

  • Anh Tran (eLightUp) Falcon – WordPress Optimizations & Tweaks <= 2.10.0

Timeline

  • 2026-04-30: other: Reported by researcher dodoh4t
  • 2026-07-23: advisory: Patchstack advisory published
  • 2026-07-27: disclosed: CVE published to NVD
  • 2026-07-27: patched: Patch available in version 2.10.1

References