What is CVE-2026-16042?
CVE-2026-16042 allows any authenticated user, including Subscribers, to flush caches on sites using the LWS Optimize WordPress plugin before version 3.4 due to a missing capability check, forcing repeated cache rebuilds. Upgrade the plugin to the latest version to mitigate this issue.
Azərbaycanca: CVE-2026-16042 LWS Optimize WordPress plugin-in 3.4-dən əvvəlki versiyalarında cache təmizləmə əməliyyatları üçün icazə yoxlaması aparılmadığından, Subscriber daxil istənilən autentifikasiya olunmuş istifadəçi saytın keşini təmizləyərək təkrar cache yenilənməsinə səbəb ola bilər. Plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What versions of the LWS Optimize plugin are affected by CVE-2026-16042?
This vulnerability affects the LWS Optimize WordPress plugin versions prior to 3.4.
What level of privilege is required to exploit CVE-2026-16042?
Any authenticated user, including Subscribers, can exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.