Medium 6.1
2026-05-01< 2.10.0
CVE-2024-13362
Minimum safe version
3.3.0
Update to 3.3.0 or later to address 8 fixable vulnerabilities
CVE-2024-13362
CVE-2026-24633
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Add Expires Headers & Optimized Minify Plugin < 2.8.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-27457
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Add Expires Headers & Optimized Minify plugin < 2.5 - Sensitive Information Disclosure vulnerability
WordPress Add Expires Headers & Optimized Minify plugin < 2.5 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability