Impact
An unauthenticated unknown vulnerability exists in the Falcon – WordPress Optimizations & Tweaks plugin version 2.10.0 or earlier. The CVSS score of 7.5 indicates a high severity level, but the public description does not specify a concrete exploitation method or impact. The vulnerability is listed as unknown, meaning the exact nature of how it can be exploited remains unspecified in the vendor or security advisory.
Affected Systems
WordPress sites installing the Falcon – WordPress Optimizations & Tweaks plugin version 2.10.0 or earlier, released by Anh Tran. No sub‑version filtering is specified, so any installation using a vulnerable version is at risk. The vulnerability applies regardless of other plugins or additional security settings present on the site.
Risk and Exploitability
Because the vulnerability is unauthenticated, it could be targeted by any user able to access the site and interact with the plugin’s endpoints. The EPSS score of less than 1% suggests that active exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. However, the high CVSS score indicates that, if an attacker succeeds, the impact could be significant, underscoring the importance of addressing the flaw promptly.
OpenCVE Enrichment