Description
The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.
Published: 2026-08-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The LWS Optimize WordPress plugin, versions before 3.4, contains a missing capability check for its cache‑clearing operations. It allows any authenticated user—including Subscribers—to flush the site’s caches, forcing repeated cache rebuilds that can exhaust server resources and degrade site performance. This flaw is a missing authorization vulnerability (CWE‑862) where a privileged operation is exposed to insufficiently privileged users.

Affected Systems

The vulnerability affects the LWS Optimize plugin in versions before 3.4, released by an unidentified vendor. No other vendors or product families are listed as impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score remains very low, with less than 1% likelihood of exploitation. It is not listed in the CISA KEV catalog. Any authenticated user can trigger the cache flush, leading to unnecessary rebuilds and potential denial of service via resource exhaustion. The lack of administrative context elevates the risk for larger sites that rely on caching for performance.

Generated by OpenCVE AI on August 5, 2026 at 00:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the LWS Optimize plugin to version 3.4 or later, which includes the correct capability check for cache clearing.
  • If an upgrade is not yet possible, disable the cache‑clearing capability for the Subscriber role using a role editor or plugin configuration settings.
  • Confirm that only users with the Administrator role retain the ability to flush the cache to ensure the vulnerability is fully mitigated.

Generated by OpenCVE AI on August 5, 2026 at 00:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 02 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.
Title LWS Optimize < 3.4 - Subscriber+ Cache Deletion
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-04T17:42:33.193Z

Reserved: 2026-07-17T09:22:18.512Z

Link: CVE-2026-16042

cve-icon Vulnrichment

Updated: 2026-08-04T17:37:12.775Z

cve-icon NVD

Status : Received

Published: 2026-08-02T06:16:38.320

Modified: 2026-08-04T18:16:45.530

Link: CVE-2026-16042

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:45:03Z

Weaknesses