{"error":0,"message":null,"data":{"name":"WP Fastest Cache &#8211; WordPress Cache Plugin","plugin":"wp-fastest-cache","link":"https:\/\/wordpress.org\/plugins\/wp-fastest-cache\/","latest":"1789298640","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"6515e1a700795a48572075067b3436a7e6bbb37a71d8179e0ff938590d97381d","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.9.1.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.1.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-20714","name":"CVE-2021-20714","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-20714","description":"[en] Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administrator privileges to delete arbitrary files on the server via unspecified vectors.","date":"2021-04-27"},{"id":"JVNDB-2021-000034","name":"WordPress plugin \"WP Fastest Cache\" vulnerable to directory traversal","link":"http:\/\/jvndb.jvn.jp\/jvndb\/JVNDB-2021-000034","description":"WordPress plugin \"WP Fastest Cache\" provided by Emre Vona contains a directory traversal vulnerability (CWE-22).  Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to the developer and coordinated on his own. After coordination was completed, this case was reported to JPCERT\/CC, and JPCERT\/CC coordinated with the developer for the publication.","date":"2021-04-27"},{"id":"967c1d420062ee8ed679b9f041a22768301eab10","name":"WordPress WP Fastest Cache plugin <= 0.9.1.6 - Authenticated Arbitrary File Deletion via Path Traversal vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-0-9-1-6-authenticated-arbitrary-file-deletion-via-path-traversal-vulnerability","description":"Authenticated Arbitrary File Deletion via Path Traversal vulnerability discovered by Gen Sato in WordPress WP Fastest Cache plugin (versions <= 0.9.1.6).","date":"2021-04-27"},{"id":"78137fdc1648428b3b887b638a1d1fdb635f9761","name":"WP Fastest Cache <= 0.9.1.6 - Authenticated (Admin+) Directory Traversal to Arbitrary File Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0916-authenticated-admin-directory-traversal-to-arbitrary-file-deletion","description":"Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administrator privileges to delete arbitrary files on the server via unspecified vectors.","date":"2021-04-27"},{"id":"23e27365-9374-4f69-a05c-084e5c9aa097","name":"WP Fastest Cache &lt; 0.9.1.7 - Authenticated Arbitrary File Deletion via Path Traversal","link":"https:\/\/wpscan.com\/vulnerability\/23e27365-9374-4f69-a05c-084e5c9aa097","description":"The plugin did not validate a path parameter, allowing administrators to delete arbitrary files on the server via a path traversal attack","date":null},{"id":"EUVD-2021-8129","name":"EUVD-2021-8129","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2021-8129","description":"Malicious code in bioql (PyPI)","date":"2025-10-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:N\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"n","i":"h","a":"h","score":"6.5","severity":"m","exploitable":"1.2","impact":"5.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:N\/I:H\/A:H","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"none","i":"high","a":"high","exploitable":"1.2","impact":"5.2"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"epss":"0.022"}},{"uuid":"d3771f787029ed8117b1ecb9ffb6d780c043b40d520c73b66695fbc2729e3aee","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-9316","name":"CVE-2015-9316","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-9316","description":"[en] The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin\/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter.","date":"2019-08-14"},{"id":"6378aa36e6382664b22c450e2b16553f9d6c2550","name":"WP Fastest Cache < 0.8.4.9 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0849-sql-injection","description":"The WP Fastest Cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin\/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter.","date":"2015-11-11"},{"id":"7233f4ff-0e19-4902-a600-9346958f0eb2","name":"WP Fastest Cache &lt;= 0.8.4.8 - Blind SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/7233f4ff-0e19-4902-a600-9346958f0eb2","description":"According to the researcher, for this vulnerability to be present WP-Polls plugin also needs to be installed.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"e942e8684a9bc69414c37d65fb004be6721bed60002b0e4343755557169df09d","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.9.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.9.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-13635","name":"CVE-2019-13635","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-13635","description":"[en] The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc\/cache.php Directory Traversal.","date":"2019-07-30"},{"id":"96f2ffb44415fd5f46d86534e019662768117a17","name":"WordPress WP Fastest Cache plugin <= 0.8.9.5 - Directory Traversal vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-0-8-9-5-directory-traversal-vulnerability","description":"Directory Traversal vulnerability found by Imre Rad in WordPress WP Fastest Cache plugin (versions <= 0.8.9.5).","date":"2019-08-14"},{"id":"b02c4d4be6fe9514d91967eb1296b1ff6753e4fd","name":"WP Fastest Cache <= 0.8.9.5 - Directory Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0895-directory-traversal","description":"The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc\/cache.php Directory Traversal.","date":"2019-07-28"},{"id":"7d42dbf7-965d-49ae-9993-4c44cffeffd9","name":"WP Fastest Cache &lt;= 0.8.9.5 - Directory Traversal","link":"https:\/\/wpscan.com\/vulnerability\/7d42dbf7-965d-49ae-9993-4c44cffeffd9","description":"The WP Fastest Cache WordPress plugin was affected by a Directory Traversal security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"n","score":"9.1","severity":"c","exploitable":"3.9","impact":"5.2"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N","score":"9.1","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"none","exploitable":"3.9","impact":"5.2"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"3713eb7f5f0afdb87c4f1ae734d257c800d46b968e4c23212ffb2f1228925e22","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-6726","name":"CVE-2019-6726","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-6726","description":"[en] The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_postratings_clear_fastest_cache and rm_folder_recursively in wpFastestCache.php mishandle ..\/ in an HTTP Referer header.","date":"2019-07-29"},{"id":"0e25265163db5777f717c108a31246dff7ac96b8","name":"WordPress WP Fastest Cache plugin <= 0.8.9.0 - Unauthenticated Arbitrary File Deletion vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-0-8-9-0-unauthenticated-arbitrary-file-deletion-vulnerability","description":"Unauthenticated Arbitrary File Deletion vulnerability found by Sebastian Neef in WordPress WP Fastest Cache plugin (versions <= 0.8.9.0).","date":"2019-03-12"},{"id":"1fbe603883e7380957deab107d764ed4db65cad2","name":"WP Fastest Cache <= 0.8.9.0 - Directory Traversal to Arbitrary File Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0890-directory-traversal-to-arbitrary-file-deletion","description":"The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_postratings_clear_fastest_cache and rm_folder_recursively in wpFastestCache.php mishandle ..\/ in an HTTP Referer header.","date":"2022-01-24"},{"id":"0983ead6-81b1-43b1-ac35-088291b933ab","name":"WP Fastest Cache &lt;= 0.8.9.0 - Unauthenticated Arbitrary File Deletion","link":"https:\/\/wpscan.com\/vulnerability\/0983ead6-81b1-43b1-ac35-088291b933ab","description":"According to the original researcher:\r\n\r\n&quot;Although a successful exploit leads to data loss and potentially a DoS against the website, because wordpress won&#039;t find important files to run, there are several requirements which need to be met:\r\n\r\n- WP Fastest Cache is installed and the cache is activated\r\n- Wordpress is configured to use &#039;pretty&#039; URL schemes, like \/&lt;data&gt;\/&lt;title&gt; etc.\r\n- WP Postratings [1] is installed\r\n- At least one ratable post or page was published&quot;","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:L","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"n","i":"h","a":"l","score":"6.5","severity":"m","exploitable":"2.2","impact":"4.2"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:L","score":"6.5","severity":"medium","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"none","i":"high","a":"low","exploitable":"2.2","impact":"4.2"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"16c25f5ca8260e5f4080aab8cc568eb9243116938574e6b2f8af9df88df8e414","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.8.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.8.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-17583","name":"CVE-2018-17583","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-17583","description":"[en] The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action.","date":"2019-04-15"},{"id":"18f279c8395aef2680b0ab1cfaf43356b33b08da","name":"WP Fastest Cache <= 0.8.8.5 - Cross-Site Scripting via the rules[0][content] parameter in a wpfc_save_exclude_pages action","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0885-cross-site-scripting-via-the-rules0content-parameter-in-a-wpfc-save-exclude-pages-action","description":"The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action.","date":"2018-10-09"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"aeeace40a9b49f60a848d6e241d0a215d37615e3c4a90db50cc555500bd9b2c8","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.8.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.8.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-17584","name":"CVE-2018-17584","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-17584","description":"[en] The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin\/admin.php wpfastestcacheoptions page.","date":"2019-04-15"},{"id":"52bf89d665f400a59ee6bac08a6039639b8e3b91","name":"WP Fastest Cache <= 0.8.8.5 - Cross-Site Request Forgery via page to wpfastestcacheoptions","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0885-cross-site-request-forgery-via-page-to-wpfastestcacheoptions","description":"The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin\/admin.php wpfastestcacheoptions page.","date":"2018-10-09"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"896ee9e8decc85a3619e0e01a71cae7daebd573a9a645703a11e5b2e6730d801","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.8.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.8.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-17586","name":"CVE-2018-17586","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-17586","description":"[en] The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pages action.","date":"2019-04-15"},{"id":"191eaeada46f4373539b37ccf72e2e67e8c1214e","name":"WP Fastest Cache <= 0.8.8.5 - Cross-Site Scripting via rules[0][content] parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0885-cross-site-scripting-via-rules0content-parameter","description":"The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pages action.","date":"2018-10-09"},{"id":"0baca08e-8122-407c-aa49-87b1dad32f96","name":"WP Fastest Cache &lt;= 0.8.8.5 - CSRF and multiple XSS","link":"https:\/\/wpscan.com\/vulnerability\/0baca08e-8122-407c-aa49-87b1dad32f96","description":"The WP Fastest Cache WordPress plugin was affected by a CSRF and multiple XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"587db6c1120c8e44615c8ddd0de3d7ec795d4149cb39f8d46817a1014e252d8c","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.8.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.8.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-17585","name":"CVE-2018-17585","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-17585","description":"[en] The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or wpFastestCacheLanguage parameter.","date":"2019-04-15"},{"id":"928b38d7ebd5165d0657b9e90ae996faecfe5df4","name":"WP Fastest Cache <= 0.8.8.5 - Cross-Site Scripting via wpFastestCachePage options, wpFastestCachePreload_number or wpFastestCacheLanguage parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0885-cross-site-scripting-via-wpfastestcachepage-options-wpfastestcachepreload-number-or-wpfastestcachelanguage-parameter","description":"The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or wpFastestCacheLanguage parameter.","date":"2018-10-09"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"d1b8240ab6ec02f8da29683b131e809d8cdfc24dcbfb240a763cfb5de29e1ebc","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.3.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.3.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-4089","name":"CVE-2015-4089","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-4089","description":"[en] Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin before 0.8.3.5 for WordPress allow remote attackers to hijack the authentication of unspecified victims for requests that call the (1) saveOption, (2) deleteCache, (3) deleteCssAndJsCache, or (4) addCacheTimeout method via the wpFastestCachePage parameter in the WpFastestCacheOptions\/ page.","date":"2017-09-19"},{"id":"93655a13c14a05338df630c9649558696cfc1ee7","name":"WP Fastest Cache < 0.8.3.5 - Multiple Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0835-multiple-cross-site-request-forgery","description":"Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin before 0.8.3.5 for WordPress allow remote attackers to hijack the authentication of unspecified victims for requests that call the (1) saveOption, (2) deleteCache, (3) deleteCssAndJsCache, or (4) addCacheTimeout method via the wpFastestCachePage parameter in the WpFastestCacheOptions\/ page.","date":"2015-05-26"},{"id":"bc8ce7e3-9a72-40a4-a74b-ff17ccaae252","name":"WP Fastest Cache &lt; 0.8.3.5 - Multiple CSRF","link":"https:\/\/wpscan.com\/vulnerability\/bc8ce7e3-9a72-40a4-a74b-ff17ccaae252","description":"The WP Fastest Cache WordPress plugin was affected by a Multiple CSRF security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"008cb2e367f241cd92a6bf36507090efdd4c5ad10e9732b49138de31ad199b11","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3a131edbea817aa9b91f6d1fa7c9fdb087c5d125","name":"WordPress WP Fastest Cache plugin <= 0.9.4 - Authenticated SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-0-9-4-authenticated-sql-injection-sqli-vulnerability","description":"Authenticated SQL Injection (SQLi) vulnerability discovered by Marc Montpas (Jetpack Scan team) in WordPress WP Fastest Cache plugin (versions <= 0.9.4).","date":"2021-10-14"}],"impact":[]},{"uuid":"99b9b0accbfb362f7ad2fc8adb78b532c5ecb8f4b40ba49bf9416613dc6e61b5","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"cade42a9e3b42294eca71dd715ca51c6dcb61b70","name":"WordPress WP Fastest Cache plugin <= 0.9.4 - Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-0-9-4-cross-site-request-forgery-csrf-vulnerability-leading-to-stored-cross-site-scripting-xss","description":"Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) discovered by Marc Montpas (Jetpack Scan team) in WordPress WP Fastest Cache plugin (versions <= 0.9.4).","date":"2021-10-14"}],"impact":[]},{"uuid":"4d9c9b625e7e5512e952fe325fe90ed1c5b5a3abb8befa673f926a612670adab","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.9.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"05d18738c5b299aff2ff5178b199b5558f597bd0","name":"WordPress WP Fastest Cache plugin <= 0.9.0.2 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-0-9-0-2-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability discovered by Glyn Wintle in WordPress WP Fastest Cache plugin (versions <= 0.9.0.2).","date":"2020-02-05"}],"impact":[]},{"uuid":"3ba42262a39756964ddf3c6b95532c2a0cd76d792c59f6b58e82347c9ae83787","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.7.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.7.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f9ba8204c1465dc1158bf5cc56efc18a01b62ed3","name":"WordPress WP Fastest Cache plugin <=0.8.7.4 - Blind SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-0-8-7-4-blind-sql-injection-sqli-vulnerability","description":"Blind SQL Injection (SQLi) vulnerability found in WordPress WP Fastest Cache plugin (versions <=0.8.7.4).","date":"2018-02-26"}],"impact":[]},{"uuid":"c946d499b357818459833818654ce9c7501f80df1117beaf212476543a63efd3","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.5.5.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.5.5.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bd2c0889e81a092330d4eaa53459c9cf75ad0bff","name":"WordPress WP Fastest Cache plugin <= 0.8.5.8 - Cross-Site Request Forgery (CSRF)\/Cross-Site Scripting (XSS) Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-0-8-5-8-cross-site-request-forgery-csrf-cross-site-scripting-xss-vulnerabilities","description":"Cross-Site Request Forgery (CSRF)\/Cross-Site Scripting (XSS) Vulnerabilities were found in WordPress WP Fastest Cache plugin <= v0.8.5.8. The settings are not sanitized and escaped so the plugin is prone to a Cross-Site Scripting (XSS) vulnerability. It also missing a nonce for the settings form.\nUpdate the plugin.","date":"2017-06-20"}],"impact":[]},{"uuid":"5b4b196fe079216f3cd9afd44c55b75d5baa64d735e560a318a83e57d6368ac8","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.6.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.6.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6136c541513fdfdb3aef545a9918f73d35c7315b","name":"WordPress Fastest Cache Plugin <= 0.8.5.9 - Local File Inclusion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-fastest-cache-plugin-0-8-5-9-local-file-inclusion","description":"This plugin is prone to a local file inclusion vulnerability. It allows  attackers to place an arbitrary PHP file on the target system.\nUpdate the plugin.","date":"2016-07-13"}],"impact":[]},{"uuid":"fbf23b09647b8c85cb54be9adb13f1c9120b75f139f00e9201c434ede075544f","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.5.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.5.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7229eb736945daae1be75d2c60a2e845c4730ce7","name":"WordPress Fastest Cache Plugin <= 0.8.5.7 - Local File Inclusion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-fastest-cache-plugin-0-8-5-7-local-file-inclusion","description":"This plugin is prone to a local file inclusion vulnerability. It allows  attackers to execute code on the target web server or on a site visitor\u2019s browser. Then they can steal data or perform a denial of service attacks.\nUpdate the plugin.","date":"2016-05-24"}],"impact":[]},{"uuid":"bc5a565c75597e91bd04b7e3c09657c3e43f5a653f00619b77891337a58df927","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"10ef82b8a089650c6c6642d1b739e4c0eefc87f6","name":"WordPress WP Fastest Cache Plugin 0.8.4.8 - Blind SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-0-8-4-8-blind-sql-injection","description":"WP Fastest Cache plugin's plugin to a blind SQL injection. This vulnerability allows  an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.\nUpdate the plugin.","date":"2015-11-11"}],"impact":[]},{"uuid":"f8a1b12a056018d4511d72646d91d7c47885755309c44121e355283425a83b6e","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24870","name":"CVE-2021-24870","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24870","description":"[en] The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some the options available via the action, which could allow attackers to make logged in high privilege users call it and set a Cross-Site Scripting payload","date":"2024-01-16"},{"id":"b0b7c1b5850d7f4545ebdaf31cbcac35fc1e14d9","name":"WP Fastest Cache < 0.9.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-095-cross-site-request-forgery-to-stored-cross-site-scripting","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 0.9.5. This is due to missing or incorrect nonce validation on the wpfc_save_cdn_integration function. This makes it possible for unauthenticated attackers to perform stored cross-site scripting attacks via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2021-10-14"},{"id":"48de63ab-2ef1-4469-8fc4-9346068bdf06","name":"WP Fastest Cache &lt; 0.9.5 - CSRF to Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/48de63ab-2ef1-4469-8fc4-9346068bdf06","description":"The plugin is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some the options available via the action, which could allow attackers to make logged in high privilege users call it and set a Cross-Site Scripting payload","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0528ce5d156cc2788d2b289dd7ed27ed8259637c8631aabc6e395a9bc2278e63","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24869","name":"CVE-2021-24869","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24869","description":"[en] The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading to an SQL injection exploitable by low privilege users such as subscriber","date":"2024-01-16"},{"id":"febb2df52bf0a0d17a0d482dd57d9bd76d9dba48","name":"WP Fastest Cache < 0.9.5 - Authenticated (Subscriber+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-095-authenticated-subscriber-sql-injection","description":"The WP Fastest Cache plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions before 0.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers subscriber-level privileges or above to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2021-10-14"},{"id":"b2233795-1a32-45fc-9d51-b6bd0a073f5b","name":"WP Fastest Cache &lt; 0.9.5 - Subscriber+ SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/b2233795-1a32-45fc-9d51-b6bd0a073f5b","description":"The plugin does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading to an SQL injection exploitable by low privilege users such as subscriber","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"389844b3577d348d3f356a0ab935d00119e5b9f0accd3cd7acd8278723f3d41c","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.9.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"344f03abb2cfaa7e34bc63e45c771413f9001e58","name":"WP Fastest Cache <= 0.9.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0902-authenticated-subscriber-arbitrary-file-deletion","description":"The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.","date":"2020-02-05"},{"id":"CVE-2020-36836","name":"CVE-2020-36836","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-36836","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.","date":"2024-10-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.0","severity":"h","exploitable":"2.8","impact":"5.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.0","severity":"high","av":"network","ac":"low","pr":"low","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.2"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"be9648af6df7ad41b8ae6a8a0ada475a940046f2c3c61b9a3628f73f2dfc4278","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.7.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.7.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a2efd79f50457e817018a4eb311c463026613ee5","name":"WP Fastest Cache <= 0.8.7.4 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0874-sql-injection","description":"The WP Fastest Cache plugin for WordPress is vulnerable to blind SQL Injection via the \u2018$comment_id\u2019 parameter in versions up to, and including, 0.8.7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for subscriber-level attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2018-02-22"}],"impact":[]},{"uuid":"88306762a680bdf0f2ebd506e373f4be39102a0b47b424709b9e95c9a5d2f938","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.6.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.6.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"190eb3b3726e510d82f86d1fc5047a11793bbbf4","name":"WP Fastest Cache <= 0.8.5.9 - Local File Inclusion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0859-local-file-inclusion","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.8.5.9 via the id POST parameter. This allows authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other \u201csafe\u201d file types can be uploaded and included. This is due to an impartial fix of https:\/\/ti.wordfence.io\/vulnerabilities\/3ebe25a7-fa4d-4e3f-b969-2ff3a8388b06.","date":"2016-07-13"}],"impact":[]},{"uuid":"020f59d2068b1be8219f5aee6b826172e5978f6f68a4d2cb8e18b0f3401432b5","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.5.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.5.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d35c2b5a51485eedeffdb52bf7a0b8f4be53bba6","name":"WP Fastest Cache <= 0.8.5.7 - Local File Inclusion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0857-local-file-inclusion","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.8.5.7 via the 'id' parameter. This allows authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other \u201csafe\u201d file types can be uploaded and included.","date":"2016-05-24"}],"impact":[]},{"uuid":"1c05b60baf6fcb82a7014401d76b11e68441814e4b133215262cbcfa88d56327","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.5.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.5.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"64812f58057b173a1f005ec44e9bb8f7c7e7f8f4","name":"WP Fastest Cache <= 0.8.5.7 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-0857-missing-authorization","description":"The WP Fastest Cache plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpfc_save_cdn_integration_ajax_request_callback() function in versions up to, and including, 0.8.5.7. This makes it possible for unauthorized attackers to redirect all CSS file, image, video, etc. requests to a potentially malicious site.","date":"2016-05-23"}],"impact":[]},{"uuid":"82c9c3271aceb7c3892b3d6909feb3bec420611b4bae8cd6cb2b84c5d74693b0","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1930","name":"CVE-2023-1930","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1930","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the wpfc_clear_cache_of_allsites_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to delete caches.","date":"2023-04-06"},{"id":"d5e47da9cadfdf2057428232a8d9f2b503afbb84","name":"WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_clear_cache_of_allsites_callback'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-missing-authorization-in-wpfc-clear-cache-of-allsites-callback","description":"The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the wpfc_clear_cache_of_allsites_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to delete caches.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"18e14d253c3a07c049c18ff9431fc6e3c1e6ecbee036c553f4bd889ecfb98a9d","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1925","name":"CVE-2023-1925","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1925","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_clear_cache_of_allsites_callback function. This makes it possible for unauthenticated attackers to clear caches via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"},{"id":"f9c761c521f57c68a4ea7ab3ce989ff64fb4ee81","name":"WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_clear_cache_of_allsites_callback'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-cross-site-request-forgery-via-wpfc-clear-cache-of-allsites-callback","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_clear_cache_of_allsites_callback function. This makes it possible for unauthenticated attackers to clear caches via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b60539b1bd5d8e03ca9dc77d047df508d01aca2c18c4e3b735b034d7b1e5c434","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1922","name":"CVE-2023-1922","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1922","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_pause_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"},{"id":"ec4df31d571b43036e96d8e862bf0bc358f53287","name":"WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_pause_cdn_integration_ajax_request_callback'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-cross-site-request-forgery-via-wpfc-pause-cdn-integration-ajax-request-callback","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_pause_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6790f434782222807f7998702335d235e609ca37e9150a185d4dcfdc752d07b8","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1923","name":"CVE-2023-1923","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1923","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_remove_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"},{"id":"c31788a60162cc8683f48c37b53af6dab1d0db1c","name":"WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_remove_cdn_integration_ajax_request_callback'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-cross-site-request-forgery-via-wpfc-remove-cdn-integration-ajax-request-callback","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_remove_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5c9ee51483fc1ab2080af5a0d3838afa8fa653e982ad72d81d3bead6ca40f1a3","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1921","name":"CVE-2023-1921","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1921","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_start_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"},{"id":"dbcd99c90ce4d88a04a24bf8cc7fe8fc863cd9bf","name":"WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_start_cdn_integration_ajax_request_callback'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-cross-site-request-forgery-via-wpfc-start-cdn-integration-ajax-request-callback","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_start_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"02914e591d00d989714d89bc774cd373abdcbfa0b6687ea9f6eb2a87ee753bf3","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1929","name":"CVE-2023-1929","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1929","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_purgecache_varnish_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to purge the varnish cache.","date":"2023-04-06"},{"id":"dd02a1c4dc7732244f98686015dfe4cd70d99d19","name":"WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_purgecache_varnish_callback'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-missing-authorization-in-wpfc-purgecache-varnish-callback","description":"The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_purgecache_varnish_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to purge the varnish cache.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"063ab0ee42b2911f94f89cb0fa7fec090e3950a221a31d6f92a37fcc00bea14d","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1924","name":"CVE-2023-1924","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1924","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_toolbar_save_settings_callback function. This makes it possible for unauthenticated attackers to change cache settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"},{"id":"11a1147988fb0c65b08f968776371aad7d4f9866","name":"WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_toolbar_save_settings_callback'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-cross-site-request-forgery-via-wpfc-toolbar-save-settings-callback","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_toolbar_save_settings_callback function. This makes it possible for unauthenticated attackers to change cache settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2173a5aaf12d5e6289f022ee762b2ff26924def9a56dd1248bf8cfbc523d1ccd","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1927","name":"CVE-2023-1927","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1927","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCssAndJsCacheToolbar function. This makes it possible for unauthenticated attackers to perform cache deletion via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"},{"id":"1b09c48dd4b47d0ee7e9a524e7b63e2c52f56b28","name":"WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'deleteCssAndJsCacheToolbar'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-cross-site-request-forgery-via-deletecssandjscachetoolbar","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCssAndJsCacheToolbar function. This makes it possible for unauthenticated attackers to perform cache deletion via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"},{"id":"fd1ed3d9-2132-4a3c-8b17-67d393969b46","name":"WP Fatest Cache &lt; 1.1.3 - Multiple CSRF","link":"https:\/\/wpscan.com\/vulnerability\/fd1ed3d9-2132-4a3c-8b17-67d393969b46","description":"The plugin does not have CSRF checks in various functions, which could allow attackers to make logged in admins perform unwanted actions (such as update CDN\/Cache settings ) via CSRF attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8a100058122d60ed55b6a0ed53a9ff93c8184978580694ea87ff9c35cfca3047","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1931","name":"CVE-2023-1931","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1931","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the deleteCssAndJsCacheToolbar function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to perform cache deletion.","date":"2023-04-06"},{"id":"c070ea84ce9f3e00d8161c7c74f8bb29757f7945","name":"WordPress  WP Fastest Cache  Plugin  <= 1.1.2 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-1-1-2-multiple-missing-authorization-vulnerability","description":"Update the WordPress WP Fastest Cache plugin to the latest available version (at least 1.1.3).\nMarco Wotschka discovered and reported this Broken Access Control vulnerability in WordPress WP Fastest Cache  Plugin.  This vulnerability has been fixed in version 1.1.3.","date":"2023-04-10"},{"id":"947d27c17da0501b0b906801e955eb0b062aab1f","name":"WP Fastest Cache <= 1.1.2 - Missing Authorization in 'deleteCssAndJsCacheToolbar'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-missing-authorization-in-deletecssandjscachetoolbar","description":"The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the deleteCssAndJsCacheToolbar function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to perform cache deletion.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"27a3f9426e2b51564368aa9619742a45d0203109c28269da01c824e2848fdda3","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1928","name":"CVE-2023-1928","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1928","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_preload_single_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to initiate cache creation.","date":"2023-04-06"},{"id":"8188c26038beec55bcec9ce4a9832884cccabe25","name":"WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_preload_single_callback'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-missing-authorization-in-wpfc-preload-single-callback","description":"The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_preload_single_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to initiate cache creation.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a3355d256b47a06aa96c9451c9c9b749fbbc483c74df27794d2b5d1aa79e8229","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1926","name":"CVE-2023-1926","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1926","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCacheToolbar function. This makes it possible for unauthenticated attackers to perform cache deletion via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"},{"id":"cf0835d65a9cdc70a3e48cde52f40d1dfc98b667","name":"WordPress  WP Fastest Cache  Plugin  <= 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-1-1-2-multiple-cross-site-request-forgery-vulnerability","description":"Update the WordPress WP Fastest Cache plugin to the latest available version (at least 1.1.3).\nMarco Wotschka discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress WP Fastest Cache  Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 1.1.3.","date":"2023-04-10"},{"id":"205e9356203b2e3e523fd7105699ea9b7d0cbf29","name":"WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'deleteCacheToolbar'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-cross-site-request-forgery-via-deletecachetoolbar","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCacheToolbar function. This makes it possible for unauthenticated attackers to perform cache deletion via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"565957a9a52c2c5b930e990d3b224c2f7b081abdd03bf62105d5d43594bcced1","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1920","name":"CVE-2023-1920","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1920","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_purgecache_varnish_callback function. This makes it possible for unauthenticated attackers to purge the varnish cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"},{"id":"79d4b4ba5f3af24ebf3db4ac00595122cf5e08f8","name":"WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_purgecache_varnish_callback'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-cross-site-request-forgery-via-wpfc-purgecache-varnish-callback","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_purgecache_varnish_callback function. This makes it possible for unauthenticated attackers to purge the varnish cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e4f2578c511508c57d21c5d6d3e71a00d52bab920ed254fa9806260dc2488057","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1919","name":"CVE-2023-1919","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1919","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_save_settings_callback function. This makes it possible for unauthenticated attackers to change cache-related settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"},{"id":"d6f8e2dd8e9e0d050e5770d62f5bdbc5ec5f4beb","name":"WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_preload_single_save_settings_callback'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-cross-site-request-forgery-via-wpfc-preload-single-save-settings-callback","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_save_settings_callback function. This makes it possible for unauthenticated attackers to change cache-related settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e7d71289adce2726a1ff7d8453f57d6f12b9fd1e8d8680042078d308d852e564","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1918","name":"CVE-2023-1918","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1918","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_callback function. This makes it possible for unauthenticated attackers to invoke a cache building action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"},{"id":"c58af5dd27fd9c619466bcf52a7a08d4c2c5c098","name":"WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_preload_single_callback'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-cross-site-request-forgery-via-wpfc-preload-single-callback","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_callback function. This makes it possible for unauthenticated attackers to invoke a cache building action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7d85b228c2203c1487e360f856a8c016d76cdc9710238205f53ce05f9625da35","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1938","name":"CVE-2023-1938","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1938","description":"[en] The WP Fastest Cache WordPress plugin before 1.1.5 does not have CSRF check in an AJAX action, and does not validate user input before using it in the wp_remote_get() function, leading to a Blind SSRF issue","date":"2023-05-30"},{"id":"72a23e0b524b2c4309817f3f9494b8edfb6a25a7","name":"WordPress  WP Fastest Cache  Plugin  < 1.1.5 is vulnerable to Server Side Request Forgery (SSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fatest-cache-plugin-1-1-5-blind-ssrf-via-csrf-vulnerability","description":"Update the WordPress WP Fastest Cache plugin to the latest available version (at least 1.1.5).\nErwan LR (WPScan) discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress WP Fastest Cache  Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system. This vulnerability has been fixed in version 1.1.5.","date":"2023-05-11"},{"id":"3b1eb48b8823cade2503e0f14861fae0a3299580","name":"WP Fastest Cache <= 1.1.4 - Authenticated(Administrator+) Blind Server Side Request Forgery via check_url","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-114-authenticatedadministrator-blind-server-side-request-forgery-via-check-url","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.1.4 via the 'check_url' function. This can allow Authenticated attackers with Administrator-level permissions to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Note that the function is also vulnerable to Cross-Site Request Forgery but this is only an issue due to the Server-Side Request Forgery capability.","date":"2023-05-02"},{"id":"92b1c6d8-51db-46aa-bde6-abdfb091aab5","name":"WP Fatest Cache &lt; 1.1.5 - Blind SSRF via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/92b1c6d8-51db-46aa-bde6-abdfb091aab5","description":"The plugin does not have CSRF check in an AJAX action, and does not validate user input before using it in the wp_remote_get() function, leading to a Blind SSRF issue\r\n\r\nNote: CSRF was fixed in 1.1.4, the SSRF in 1.1.5","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."},{"cwe":"CWE-918","name":"Server-Side Request Forgery (SSRF)","description":"The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"3844b5a02d1f78b130fc9300789832c39145d1d5f15b3ec918c3532631fd7a06","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1375","name":"CVE-2023-1375","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1375","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized cache deletion in versions up to, and including, 1.1.2 due to a missing capability check in the deleteCacheToolbar function . This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the site's cache.","date":"2023-06-09"},{"id":"75083c039cbeb8a52cd61434e28003d72cb8f4e4","name":"WP Fastest Cache <= 1.1.2 - Missing Authorization to Cache Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-112-missing-authorization-to-cache-deletion","description":"The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized cache deletion in versions up to, and including, 1.1.2 due to a missing capability check in the deleteCacheToolbar function . This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the site's cache.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c509857ba22b434534b86236e7acc44c9268f09009eaa264c24d90f99f514c53","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.7.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.7.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8beb9013-b36d-4d2d-9042-f1053e2ccf21","name":"WP Fastest Cache &lt;= 0.8.7.4 - Blind SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/8beb9013-b36d-4d2d-9042-f1053e2ccf21","description":"Improper escaping of user input when deleting the cache of specific pages leads to SQL injection vulnerability. esc_sql() was used on input but the result was used unquoted in the constructed SQL query.","date":null}],"impact":[]},{"uuid":"65ba28e742abe5d4923374b574bb71bbf03e2a7fc4b63a0d0b4af7e56647368d","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.5.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.5.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1c9e81b9-8a7c-44ce-8c8d-2edb35ae44a1","name":"WP Fastest Cache &lt;= 0.8.5.9 - Local File Inclusion (LFI)","link":"https:\/\/wpscan.com\/vulnerability\/1c9e81b9-8a7c-44ce-8c8d-2edb35ae44a1","description":"The WP Fastest Cache WordPress plugin was affected by a Local File Inclusion (LFI) security vulnerability.","date":null}],"impact":[]},{"uuid":"152f3c7913e34e5e238442cf7d89a5430edc1d06e918e53f84b1b8a7348c27c3","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.8.5.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.8.5.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"12e48d35-fe72-4d6f-adc6-da41421d6239","name":"WP Fastest Cache &lt;= 0.8.5.7 - Local File Inclusion (LFI)","link":"https:\/\/wpscan.com\/vulnerability\/12e48d35-fe72-4d6f-adc6-da41421d6239","description":"The WP Fastest Cache WordPress plugin was affected by a Local File Inclusion (LFI) security vulnerability.","date":null}],"impact":[]},{"uuid":"6e0dcf33d1825c7c048bbabfa74012cee2e54c02e814637bc9940011ac35eeb7","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.9.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1fb5a8a0-4769-4e1a-9119-a63afd9364cc","name":"WP Fastest Cache &lt; 0.9.0.3 - Cross-Site Request Forgery (CSRF) Arbitrary File Deletion","link":"https:\/\/wpscan.com\/vulnerability\/1fb5a8a0-4769-4e1a-9119-a63afd9364cc","description":"The plugin did not have a CSRF nonce check on the &quot;wpfc_delete_current_page_cache&quot; action, allowing CSRF attacks against authenticated users to delete arbitrary files, including the wp-config.php file.","date":null}],"impact":[]},{"uuid":"cc51d844e383914bf9e0192569dc66cb6db0acccd675350410283e8bb0b66a03","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6063","name":"CVE-2023-6063","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6063","description":"[en] The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.","date":"2023-12-04"},{"id":"d0166a41c8163e0722cc6bb98bcf348b7985d500","name":"WP Fastest Cache <= 1.2.1 - Unauthenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-122-unauthenticated-sql-injection","description":"The WP Fastest Cache plugin for WordPress is vulnerable to SQL Injection via the '$username' variable retrieved via user cookies in all versions up to, and including, 1.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2023-11-13"},{"id":"f6b43629d85777bf2da7f367b90cede6bea61b59","name":"WordPress  WP Fastest Cache  Plugin  < 1.2.2 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-1-2-2-unauthenticated-sql-injection-vulnerability","description":"Update the WordPress WP Fastest Cache plugin to the latest available version (at least 1.2.2).\nAlex Sanford discovered and reported this SQL Injection vulnerability in WordPress WP Fastest Cache  Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 1.2.2.","date":"2023-11-14"},{"id":"30a74105-8ade-4198-abe2-1c6f2967443e","name":"WP Fastest Cache &lt; 1.2.2 - Unauthenticated SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/30a74105-8ade-4198-abe2-1c6f2967443e","description":"The plugin does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"0160e81e6ca254c71c608aa0fe6d9de9da3fb063b9e801fe0269bbaeec7991e0","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.2.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4347","name":"CVE-2024-4347","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4347","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the specificDeleteCache function. This makes it possible for authenticated attackers to delete arbitrary files on the server, which can include wp-config.php files of the affected site or other sites in a shared hosting environment.","date":"2024-05-23"},{"id":"c48e14fd3fdf8198db6a418c8889c0c9a0324c0f","name":"WP Fastest Cache <= 1.2.6 - Authenticated (Administrator+) Arbitrary File Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-126-authenticated-administrator-arbitrary-file-deletion","description":"The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the specificDeleteCache function. This makes it possible for authenticated attackers to delete arbitrary files on the server, which can include wp-config.php files of the affected site or other sites in a shared hosting environment.","date":"2024-05-10"},{"id":"944430374e5900fddd73fff93dc9f6cf9c69853e","name":"WordPress WP Fastest Cache Plugin <= 1.2.6 is vulnerable to Arbitrary File Deletion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-1-2-6-authenticated-administrator-arbitrary-file-deletion-vulnerability","description":"<p>WordPress WP Fastest Cache Plugin <= 1.2.6 is vulnerable to Arbitrary File Deletion<\/p><p>Software: WP Fastest Cache<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-fastest-cache\/#developers<\/p><p>Affected Version <= 1.2.6<\/p><p>Fixed in version 1.2.7 <\/p>","date":"2024-05-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"fa0546440e7214a311a149fa403efe5be4fce837eee50d1bd1743dbc825e19b2","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-10476","name":"CVE-2025-10476","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-10476","description":"[en] The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to initiate several database fix actions. This only affects sites with premium activated.","date":"2025-11-27"},{"id":"b5eae85ae0c3da6a830b2f347729b949ee4275ed","name":"WP Fastest Cache <= 1.4.0 - Missing Authorization to Authenticated (Subscriber+) DB Cleanup Actions","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-140-missing-authorization-to-authenticated-subscriber-db-cleanup-actions","description":"The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to initiate several database fix actions. This only affects sites with premium activated.","date":"2025-11-26"},{"id":"EUVD-2025-199817","name":"EUVD-2025-199817","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-199817","description":"The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to initiate several database fix actions. This only affects sites with premium activated.","date":"2025-11-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d536141534a1b60379a26ae80cad8be557976d95d9d74e1286ad2cc28c940125","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-74932","name":"CVE-2026-74932","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-74932","description":"[en] The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated attackers to poison cached pages with references to a server they control and have arbitrary JavaScript run for every subsequent visitor.","date":"2026-08-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"7.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"7.5","severity":"high","av":"network","ac":"high","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"4dc2685135ca804ff3ab4e86f72d83772e0db133af82b8df742c07329dde1d52","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-19760","name":"CVE-2026-19760","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-19760","description":"[en] The WP Fastest Cache \u2013 WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP Host Header in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the Polylang or Polylang Pro plugin to be active and the Combine JS option to be enabled, as these conditions trigger the vulnerable Host-header-to-URL code path that writes attacker-controlled script src values into the shared page-cache file served to all subsequent visitors.","date":"2026-08-26"},{"id":"159421bd51a4bcaf3d6aa82641c75f3126ff959a","name":"WP Fastest Cache <= 1.5.0 - Unauthenticated Stored Cross-Site Scripting via HTTP Host Header","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-fastest-cache\/wp-fastest-cache-150-unauthenticated-stored-cross-site-scripting-via-http-host-header","description":"The WP Fastest Cache \u2013 WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP Host Header in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the Polylang or Polylang Pro plugin to be active and the Combine JS option to be enabled, as these conditions trigger the vulnerable Host-header-to-URL code path that writes attacker-controlled script src values into the shared page-cache file served to all subsequent visitors.","date":"2025-11-26"},{"id":"c22daa499955a2835c0fed48fce47dda561514b8","name":"WordPress WP Fastest Cache Plugin <= 1.5.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-fastest-cache\/vulnerability\/wordpress-wp-fastest-cache-plugin-1-5-0-unauthenticated-stored-cross-site-scripting-via-http-host-header-vulnerability","description":"<p>WordPress WP Fastest Cache Plugin <= 1.5.0 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: WP Fastest Cache<\/p><p>Fixed in version 1.5.1 <\/p><p>Affected Version <= 1.5.0<\/p><p>CVE: CVE-2026-19760<\/p>","date":"2026-08-26"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2f6d3f3798775753bfc2c8beeb841d1a2d7ea84ec64dea72a79b8652e5ef10f0","name":"WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-74916","name":"CVE-2026-74916","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-74916","description":"[en] The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored under, and served from, the clean URL's cache entry to every subsequent visitor.","date":"2026-09-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-349","name":"Acceptance of Extraneous Untrusted Data With Trusted Data","description":"The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1788328996"}