Wpfastestcache Wp Fastest Cache vulnerabilities
29 known vulnerabilities affecting wpfastestcache/wp_fastest_cache.
Total CVEs
29
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM21
Vulnerabilities
Page 2 of 2
CVE-2021-20714MEDIUMCVSS 6.5fixed in 0.9.1.72021-04-27
CVE-2021-20714 [MEDIUM] CWE-22 CVE-2021-20714: Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote atta
Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administrator privileges to delete arbitrary files on the server via unspecified vectors.
nvd
CVE-2015-9316CRITICALCVSS 9.8fixed in 0.8.4.92019-08-14
CVE-2015-9316 [CRITICAL] CWE-89 CVE-2015-9316: The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.ph
The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter.
nvd
CVE-2019-13635CRITICALCVSS 9.1≤ 0.8.9.52019-07-30
CVE-2019-13635 [CRITICAL] CWE-22 CVE-2019-13635: The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.ph
The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal.
nvd
CVE-2019-6726MEDIUMCVSS 6.5≤ 0.8.9.02019-07-29
CVE-2019-6726 [MEDIUM] CWE-22 CVE-2019-6726: The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrar
The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_postratings_clear_fastest_cache and rm_folder_recursively in wpFastestCache.php mishandle ../ in an HTTP Referer header.
nvd
CVE-2018-17584HIGHCVSS 8.8v0.8.8.52019-04-15
CVE-2018-17584 [HIGH] CWE-352 CVE-2018-17584: The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcache
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.
nvd
CVE-2018-17583MEDIUMCVSS 6.1v0.8.8.52019-04-15
CVE-2018-17583 [MEDIUM] CWE-79 CVE-2018-17583: The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a w
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action.
nvd
CVE-2018-17586MEDIUMCVSS 6.1v0.8.8.52019-04-15
CVE-2018-17586 [MEDIUM] CWE-79 CVE-2018-17586: The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a w
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pages action.
nvd
CVE-2018-17585MEDIUMCVSS 6.1v0.8.8.52019-04-15
CVE-2018-17585 [MEDIUM] CWE-79 CVE-2018-17585: The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCac
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or wpFastestCacheLanguage parameter.
nvd
CVE-2015-4089HIGHCVSS 8.8≤ 0.8.3.42017-09-19
CVE-2015-4089 [HIGH] CWE-352 CVE-2015-4089: Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in adm
Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin before 0.8.3.5 for WordPress allow remote attackers to hijack the authentication of unspecified victims for requests that call the (1) saveOption, (2) deleteCache, (3) deleteCssAndJsCache, or (4) addCacheTimeout method vi
nvd
← Previous2 / 2