CVE-2025-8778
Published
CVSS v3
4.3
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the nitropack_set_compression_ajax() function in all versions up to, and including, 1.18.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the nitropack-enableCompression option and effectively change plugin compression settings.
<p>Speed up your WordPress site, achieve a 90+ Performance score on PageSpeed Insights, and pass your Core Web Vitals with NitroPack.</p>
<p>Boost your website’s speed effortlessly with NitroPack, the ultimate solution trusted by hundreds of thousands worldwide to climb Google rankings, boost conversions, and expand businesses. NitroPack stands above traditional caching with its cloud-based infrastructure and advanced optimizations, delivering <a href="https://lookerstudio.google.com/s/p0XCJZ_3A5o" rel="nofollow ugc">top scores on Core Web Vitals</a> and Lighthouse tests. This ensures a seamless, fast experience for your visitors.</p>
<p>Experience unmatched performance with features like cutting-edge caching, full image optimization, code optimization, an integrated global CDN, and lazy loading. NitroPack is your all-in-one tool for a lightning-fast website that captivates visitors and drives conversions.</p>
<p><span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/jLzYUKSo5Jo?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p>
<h3>Why choose NitroPack?</h3>
<ul>
<li>
<p><strong>Instant Performance Boost Without Coding</strong>:<br />
NitroPack delivers a significant website speed and performance boost instantly, eliminating the need for complex coding or technical expertise. Enjoy faster page load speed, improved page speed scores, and better user experience effortlessly.</p>
</li>
<li>
<p><strong>Automated Optimization for Core Web Vitals</strong>:<br />
NitroPack automates the optimization of <a href="https://youtu.be/h9V4oL5DQ9M?list=PLxSs9-caejlWX3fbP5iJ0S0-juOhSJgzO" rel="nofollow ugc">Core Web Vitals</a>, ensuring your website consistently meets and exceeds the page experience metrics that impact user experience, SEO, and search engine rankings. Learn more about how we can help you boost your Core Web Vitals scores with our latest webinars with Google.</p>
</li>
<li>
<p><strong>Optimizations with Zero Impact on Your Hosting’s CPU and RAM</strong>:<br />
NitroPack handles all resource-intensive performance optimization tasks, including caching, image optimization, and file minification, on its own servers. This preserves your hosting resources while improving website speed and page performance without putting strain on your server’s CPU or RAM.</p>
</li>
</ul>
<p>An additional customer-centric approach safeguards your site’s performance and stability by working on copies of your files, meaning your original content stays unchanged. With NitroPack, you can optimize page speed and user experience confidently, knowing your website’s integrity is protected.</p>
<p><a href="https://nitropack.io/?utm_source=wp-repo&utm_medium=link&utm_term=description&utm_campaign=WP-plugin&utm_content=speed-up-your-site-with-nitropack" rel="nofollow ugc">Speed up your site with NitroPack</a></p>
<h3>✅ What’s included in the Free plan?</h3>
<p>NitroPack’s Free plan* is recommended for small websites and testing website speed optimization. Install it on up to 1 website (no CC required) and experience the powerful performance and cache optimizations we offer firsthand before committing to our <a href="https://nitropack.io/pricing?utm_source=wp-repo&utm_medium=link&utm_campaign=WP-plugin&utm_id=wp-repo&utm_term=description&utm_content=paid-subscriptions" rel="nofollow ugc">paid subscriptions</a>, starting at $7/mo.</p>
<p>With up to 1,000 pageviews and 1GB of CDN bandwidth included monthly, you can leverage over 35 of NitroPack’s speed optimization features across Caching, Image and Media, JavaScript, HTML and CSS, and Fonts.</p>
<p>Within seconds of installation, NitroPack applies the following features automatically to boost page speed, improve site speed, and fix common WordPress performance issues:</p>
<ul>
<li><strong>Caching</strong>: Minify Resources, Ignored parameters, Cache Reset, Excluded resources, Excluded URLs, Dynamic content cookies, Advanced caching, Smart cache invalidation, Light Purge, Device-aware caching, Integration with 3rd-party cache, Cache Warmup</li>
<li><strong>Image and Media</strong>: Lazy load images, Lazy load iframes, Video facades, Lossless and Lossy Image Optimization, WebP Conversion, Preemptive Image Sizing, Lazy loading of background images</li>
<li><strong>JavaScript</strong>: Remove render-blocking resources, JS Minification, Third-party Scripts Optimization</li>
<li><strong>HTML and CSS</strong>: Keep HTML comments, HTML normalization, Generate critical CSS, Custom CSS, Combine CSS, CSS Minification, Advanced CSS Management, Advanced Resource Loader, HTML Minification, Page prefetching and prerendering</li>
<li><strong>Fonts</strong>: Override Font Rendering Behavior</li>
<li><strong>CDN</strong>: Static Content Caching, GZIP and Brotli Compression, HTTP/3 Compatibility.</li>
</ul>
<p>For questions and technical assistance, customers on the free plan can rely on our 24/7 ticketing support system.</p>
<h3>What makes NitroPack the ultimate speed optimizer?</h3>
<h3>💾 ADVANCED CACHING:</h3>
<p>Thanks to its advanced features and smart caching system, NitroPack ensures fast and stable website performance, even during traffic spikes.</p>
<ul>
<li><strong>Automatic Cache Warmup:</strong> Preloads cached pages to ensure fast delivery from the first visit</li>
<li><strong>Smart Cache Invalidation:</strong> Keeps cached content fresh without unnecessary cache resets</li>
<li><strong>Device- and Cookie-Aware Caching:</strong> Delivers optimized cache versions for different devices and users for a tailored and fast user experience.</li>
<li><strong>Browser Cache:</strong> Improves load speed for returning visitors by leveraging the built-in browser cache</li>
</ul>
<h3>🖼️ IMAGE OPTIMIZATION:</h3>
<p>NitroPack eliminates manual image optimization by automatically reducing image size by up to 7x while preserving quality, dramatically improving page speed and user experience.</p>
<ul>
<li><strong>Automatic Image Optimization:</strong> Dynamically resizes images, converts them to WebP format, and applies the best compression technique to reduce file sizes without sacrificing quality</li>
<li><strong>Adaptive Image Sizing:</strong> Optimizes images to perfectly fit their display containers across devices for an enhanced user experience</li>
<li><strong>Advanced Lazy Loading:</strong> Improves page load speed by loading offscreen images and videos (including GIFs, YouTube, Vimeo, and Wistia) only when needed</li>
</ul>
<h3>🌐 BUILT-IN GLOBAL CDN:</h3>
<p>NitroPack includes a global Content Delivery Network (CDN) powered by Cloudflare, delivering content from hundreds of servers across 120+ countries.</p>
<ul>
<li><strong>Ultra-fast CDN delivery</strong> for static and dynamic content, regardless of your users’ location</li>
<li><strong>GZIP & Brotli compression</strong> for faster data transfer</li>
<li><strong>HTTP/3 support</strong> for modern, high-performance connections</li>
</ul>
<h3>🛠️ CODE OPTIMIZATION:</h3>
<p>NitroPack’s code optimization engine improves page speed and performance by optimizing HTML, CSS, and JavaScript automatically.</p>
<ul>
<li><strong>Advanced Resource Loader</strong> for intelligent management of resource loading without the need for technical intervention</li>
<li><strong><a href="https://nitropack.io/blog/post/critical-css?utm_source=wp-repo&utm_medium=link&utm_campaign=WP-plugin&utm_content=critical-css" rel="nofollow ugc">Critical CSS optimization</a></strong> that prioritizes above-the-fold CSS for rapid page rendering, making your site appear faster to users</li>
<li><strong>Deferred JavaScript loading</strong> for improved page responsiveness</li>
<li><strong>CSS & JS combining and minification</strong> for improved loading efficiency, reduced HTTP requests, and faster overall site speed.</li>
<li><strong>HTML compression</strong> and <a href="https://nitropack.io/blog/post/resource-hints-performance-optimization?utm_source=wp-repo&utm_medium=link&utm_campaign=WP-plugin&utm_content=DNC-prefetching-preloarding" rel="nofollow ugc">DNS preconnects</a> reduce the time it takes to fetch external resources</li>
</ul>
<h3>✏️ FONT OPTIMIZATION:</h3>
<p>Improve website speed by optimizing web fonts by over 60%, including Google Fonts, without sacrificing design.</p>
<ul>
<li><strong><a href="https://nitropack.io/blog/post/font-subsetting-nitropack?utm_source=wp-repo&utm_medium=link&utm_campaign=WP-plugin&utm_content=font-subsetting" rel="nofollow ugc">Font subsetting</a></strong> to remove unused glyphs on the page</li>
<li><strong>Deferred font loading</strong> for better page experience</li>
<li><strong>Font compression (WOFF2)</strong> to reduce font file size by up to 50%</li>
<li><strong>Google Fonts optimization</strong> via hosting them on our CDN</li>
</ul>
<p>To view a complete list of NitroPack’s features, <a href="https://nitropack.io/page/features?utm_source=wp-repo&utm_medium=link&utm_term=description&utm_campaign=WP-plugin&utm_content=feature-page" rel="nofollow ugc">visit the feature page</a>.</p>
<h3>☎️ 24/7 SUPPORT:</h3>
<p>All NitroPack customers receive expert live chat support and access to an extensive knowledge base for site speed, performance, and cache-related issues.</p>
<h3>🔒 SECURITY AND COMPLIANCE:</h3>
<p>Your safety is our priority. NitroPack is SOC2 Type 2 compliant and ISO 27001 certified, internationally recognized standards for managing information security. We have a devoted team of security specialists working around the clock to uphold the highest level of security and compliance. By implementing industry-leading practices, we ensure your data remains secure and your peace of mind intact, while optimizing website performance.</p>
<h3>🔌 COMPATIBILITIES:</h3>
<p>NitroPack integrates seamlessly with the most popular WordPress plugins and themes to provide a smooth user experience:</p>
<h3>Plugins:</h3>
<ul>
<li>WooCommerce</li>
<li>Elementor</li>
<li>Divi Builder</li>
<li>Yoast SEO</li>
<li>Squirrly SEO</li>
<li>All in One SEO Pack</li>
<li>Rank Math SEO</li>
<li>Contact Form 7</li>
<li>WPML</li>
<li>Cloudflare</li>
<li>WPForms</li>
<li>Gravity Forms</li>
<li>WPBakery</li>
<li>Beaver Builder</li>
<li>Fusion Page Builder</li>
<li>Thrive Architect</li>
<li>HubSpot</li>
<li>All-in-one WP Migration</li>
<li>OptinMonster</li>
<li>Drift Chat</li>
<li>LiveChat</li>
<li>Tawk.to Chat</li>
<li>ShortPixel</li>
<li>GeoTargeting WP</li>
<li>Mediavine</li>
<li>MainWP</li>
<li>And more</li>
</ul>
<h3>Themes:</h3>
<ul>
<li>Astra</li>
<li>OceanWP</li>
<li>Neve</li>
<li>GeneratePress</li>
<li>Avada</li>
<li>BeTheme</li>
<li>Divi</li>
<li>X</li>
<li>Enfold</li>
<li>Sena</li>
<li>Jupiter</li>
<li>Thrive</li>
<li>Davenport</li>
<li>And more</li>
</ul>
<h3>SHARE THE NITRO 💜</h3>
<p>Join our <a href="https://www.facebook.com/groups/nitropack.community/" rel="nofollow ugc">Facebook Community</a>.<br />
Learn from our tutorials on <a href="https://www.youtube.com/@nitropack/videos" rel="nofollow ugc">YouTube Channel</a>.<br />
Contribute to <a href="https://translate.wordpress.org/projects/wp-plugins/nitropack/" rel="nofollow ugc">NitroPack’s translations</a><br />
Or rate us on <a href="https://wordpress.org/support/plugin/nitropack/reviews/" rel="ugc">WordPress</a> 🙂</p>
<p>*The Free plan includes a small NitroPack badge in the footer to show visitors the website runs on top-tier performance optimization tech.</p>