CVE-2025-8147: LWSCache <= 2.8.5 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation via lwscache_activatePlugin Function
The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on the lwscacheactivatePlugin() function in all versions up to, and including, 2.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate arbitrary whitelisted LWS plugins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8147?
CVE-2025-8147 has a medium severity rating due to the potential for unauthorized data modification by authenticated attackers.
How do I fix CVE-2025-8147?
To fix CVE-2025-8147, update the LWSCache plugin to version 2.8.6 or later where the vulnerability has been patched.
Who is affected by CVE-2025-8147?
All users of the LWSCache plugin for WordPress running versions up to and including 2.8.5 are affected by CVE-2025-8147.
What type of vulnerability is CVE-2025-8147?
CVE-2025-8147 is an authorization vulnerability that allows improper modifications of data in the LWSCache plugin.
Can unauthenticated users exploit CVE-2025-8147?
No, CVE-2025-8147 requires authenticated users with Subscriber-level access to exploit the vulnerability.