CyberRota Analysis
AI-GeneratedThe LWS Optimize WordPress plugin prior to version 3.4 is vulnerable as it lacks proper capability checks for its cache-clearing functionality, enabling any authenticated user, including those with minimal permissions like Subscribers, to flush site caches. This could lead to performance degradation and potential denial of service due to excessive cache rebuilds. WordPress site administrators should prioritize updating this plugin to mitigate the risk of abuse by unauthorized users.
Original NVD Description
The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.