Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wp fastest cache vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2021-24870
The WP Fastest Cache WordPress plugin prior to 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some the options available via the action, which could allow malicious users to make logged in high privilege users call it ...
Wpfastestcache Wp Fastest Cache
7.5
CVSSv3
CVE-2023-6063
The WP Fastest Cache WordPress plugin prior to 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
Wpfastestcache Wp Fastest Cache
7 Github repositories
4.3
CVSSv3
CVE-2023-1927
The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCssAndJsCacheToolbar function. This makes it possible for unauthenticated malicious use...
Wpfastestcache Wp Fastest Cache
6.1
CVSSv3
CVE-2018-17583
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action.
Wpfastestcache Wp Fastest Cache 0.8.8.5
8.8
CVSSv3
CVE-2018-17584
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.
Wpfastestcache Wp Fastest Cache 0.8.8.5
6.1
CVSSv3
CVE-2018-17585
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or wpFastestCacheLanguage parameter.
Wpfastestcache Wp Fastest Cache 0.8.8.5
6.1
CVSSv3
CVE-2018-17586
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pages action.
Wpfastestcache Wp Fastest Cache 0.8.8.5
6.5
CVSSv3
CVE-2021-20714
Directory traversal vulnerability in WP Fastest Cache versions before 0.9.1.7 allows a remote attacker with administrator privileges to delete arbitrary files on the server via unspecified vectors.
7.2
CVSSv3
CVE-2024-4347
The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the specificDeleteCache function. This makes it possible for authenticated malicious users to delete arbitrary files on the server, which can include wp-...
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3