CVE-2024-5810 Information
Description
The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to and including 1.0.1. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers to overwrite CSS update the trial settings purge the cache and find attachments.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Reference
https://www.wordfence.com/threat-intel/vulnerabilities/id/1fe97ac1-cab9-4b6f-bddd-bdcdc9faee40?source=cve https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L71 https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L263 https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L372 https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L152 https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L165
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
5.3
Share on: