CVE-2026-16042: LWS Optimize < 3.4 - Subscriber+ Cache Deletion
Published Aug 2, 2026
·Updated
The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.
Affected Software
1 affected component
WordPress LWS Optimize<3.4
Event History
Aug 2, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-16042?
CVE-2026-16042 is rated with a risk score of 32, indicating a medium severity level.
2
How do I fix CVE-2026-16042?
To fix CVE-2026-16042, update the LWS Optimize plugin to version 3.4 or later.
3
What is affected by CVE-2026-16042?
CVE-2026-16042 affects the LWS Optimize WordPress plugin versions prior to 3.4.
4
Who can exploit CVE-2026-16042?
Any authenticated user, including Subscribers, can exploit CVE-2026-16042 to flush the site's caches.
5
What are the potential consequences of CVE-2026-16042?
The potential consequences of CVE-2026-16042 include unauthorized cache flushing and performance issues due to repeated cache rebuilds.