{"id":"CVE-2026-16042","title":"The LWS Optimize  WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.","summary":"The LWS Optimize  WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.","severity":"none","published":"2026-08-02","updated":"2026-08-02","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-16042","references":[{"url":"https://wpscan.com/vulnerability/0ea45a09-3155-4e47-97f7-f7645d583565/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-08-02T13:18:29.204Z","epss":0.00195,"epssPercentile":0.09427,"slug":"CVE-2026-16042","body":"## Overview\n\nThe LWS Optimize  WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}