{"api_version":"1","generated_at":"2026-07-24T19:58:17+00:00","cve":"CVE-2024-5810","urls":{"html":"https://cve.report/CVE-2024-5810","api":"https://cve.report/api/cve/CVE-2024-5810.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2024-5810","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2024-5810"},"summary":{"title":"WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 <= 1.0.1 - Improper Authorization due to use of Hardcoded Credentials","description":"The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers to overwrite CSS, update the trial settings, purge the cache, and find attachments.","state":"PUBLISHED","assigner":"Wordfence","published_at":"2024-07-09 09:15:07","updated_at":"2026-04-08 17:19:06"},"problem_types":["CWE-798","CWE-798 CWE-798 Use of Hard-coded Credentials"],"metrics":[{"version":"3.1","source":"security@wordfence.com","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","data":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L372","name":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L372","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L263","name":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L263","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L71","name":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L71","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L165","name":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L165","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L152","name":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L152","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1fe97ac1-cab9-4b6f-bddd-bdcdc9faee40?source=cve","name":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1fe97ac1-cab9-4b6f-bddd-bdcdc9faee40?source=cve","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-5810","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-5810","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"wp2speed","product":"WP2Speed Faster – Optimize PageSpeed Insights Score 90-100","version":"affected 1.0.1 semver","platforms":[]},{"source":"ADP","vendor":"wp2speed","product":"wp2speed","version":"affected 1.0.1 custom","platforms":[]}],"timeline":[{"source":"CNA","time":"2024-07-08T19:47:02.000Z","lang":"en","value":"Disclosed"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Lucio Sá","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"affected":[{"cpes":["cpe:2.3:a:wp2speed:wp2speed:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"wp2speed","vendor":"wp2speed","versions":[{"lessThanOrEqual":"1.0.1","status":"affected","version":"0","versionType":"custom"}]}],"metrics":[{"other":{"content":{"id":"CVE-2024-5810","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2024-07-09T14:24:50.791970Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2024-07-10T16:30:44.152Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2024-08-01T21:25:02.726Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_transferred"],"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1fe97ac1-cab9-4b6f-bddd-bdcdc9faee40?source=cve"},{"tags":["x_transferred"],"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L71"},{"tags":["x_transferred"],"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L263"},{"tags":["x_transferred"],"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L372"},{"tags":["x_transferred"],"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L152"},{"tags":["x_transferred"],"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L165"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"WP2Speed Faster – Optimize PageSpeed Insights Score 90-100","vendor":"wp2speed","versions":[{"lessThanOrEqual":"1.0.1","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Lucio Sá"}],"descriptions":[{"lang":"en","value":"The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers to overwrite CSS, update the trial settings, purge the cache, and find attachments."}],"metrics":[{"cvssV3_1":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-798","description":"CWE-798 Use of Hard-coded Credentials","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-04-08T16:41:07.760Z","orgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","shortName":"Wordfence"},"references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1fe97ac1-cab9-4b6f-bddd-bdcdc9faee40?source=cve"},{"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L71"},{"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L263"},{"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L372"},{"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L152"},{"url":"https://plugins.trac.wordpress.org/browser/wp2speed/trunk/lib/includes/optimize.php#L165"}],"timeline":[{"lang":"en","time":"2024-07-08T19:47:02.000Z","value":"Disclosed"}],"title":"WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 <= 1.0.1 - Improper Authorization due to use of Hardcoded Credentials"}},"cveMetadata":{"assignerOrgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","assignerShortName":"Wordfence","cveId":"CVE-2024-5810","datePublished":"2024-07-09T08:33:03.671Z","dateReserved":"2024-06-10T19:17:36.398Z","dateUpdated":"2026-04-08T16:41:07.760Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2024-07-09 09:15:07","lastModifiedDate":"2026-04-08 17:19:06","problem_types":["CWE-798","CWE-798 CWE-798 Use of Hard-coded Credentials"],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2024","CveId":"5810","Ordinal":"1","Title":"WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 <= 1.","CVE":"CVE-2024-5810","Year":"2024"},"notes":[{"CveYear":"2024","CveId":"5810","Ordinal":"1","NoteData":"The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers to overwrite CSS, update the trial settings, purge the cache, and find attachments.","Type":"Description","Title":"WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 <= 1."}]}}}