N/A
2025-09-09< 1.18.5
NitroPack <= 1.18.4 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update via nitropack_set_compression_ajax Function
Minimum safe version
1.19.4
Update to 1.19.4 or later to address 8 fixable vulnerabilities
NitroPack <= 1.18.4 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update via nitropack_set_compression_ajax Function
CVE-2026-39669
CVE-2024-11848
CVE-2024-11851
CVE-2024-43922
NitroPack < 1.10.0 - Missing Authorization via multiple AJAX functions
WordPress NitroPack Plugin <= 1.10.2 is vulnerable to Cross Site Request Forgery (CSRF)
NitroPack <= 1.9.2 - Missing Authorization via multiple AJAX functions