NitroPack WordPress Plugin Missing Authorization Vulnerability in Compression Settings Update

Vulnerability

A vulnerability exists in the NitroPack plugin for WordPress, allowing unauthorized data modification. This issue arises from a missing capability check in the 'nitropack_set_compression_ajax()' function, affecting all versions up to and including 1.18.4. The flaw enables authenticated attackers with Subscriber-level access or higher to alter the 'nitropack-enableCompression' option, thereby changing the plugin's compression settings.

Impact

Exploitation of this vulnerability allows for unauthorized changes to the NitroPack plugin's compression settings, which could disrupt website performance optimization.

Reproduction

To reproduce this vulnerability, an authenticated user with Subscriber-level access must send a request to the 'nitropack_set_compression_ajax()' function without the necessary capability. This can be done by omitting the authorization check that normally prevents unauthorized users from modifying compression settings.

Remediation

Users are advised to update the NitroPack WordPress plugin to version 1.18.5 or later, where this vulnerability has been patched.

Added: Sep 10, 2025, 7:30 AM
Updated: Sep 10, 2025, 7:30 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
6.4
remediation
7.7
relevance
0.5
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.