WordPress security by component
Wp Fastest Cache
Plugin description
Wp Fastest Cache improves WordPress page delivery by creating cached versions of pages and providing cache management settings.
Wp Fastest Cache (wp-fastest-cache) is a WordPress plugin with 34 published CVE records in this archive. The latest tracked vulnerability was published Sep 01, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
wp-fastest-cacheLatest vulnerability
CVE-2026-74916: WP Fastest Cache permits unauthenticated web-cache poisoning
WP Fastest Cache before 1.5.1 caches pages requested with certain tracking query parameters without incorporating those parameters into the cache key. An unauthenticated attacker can have a page rendered in the attacker's request context stored under the clean URL and served to subsequent visitors.
| Safe version |
|
||
|---|---|---|---|
| Sep 01, 2026 |
CVE-2026-74916
WP Fastest Cache permits unauthenticated web-cache poisoning
WP Fastest Cache before 1.5.1 caches pages requested with certain tracking query parameters without incorporating those parameters into the cache key. An unauthenticated attacker can have a page rendered in the attacker's request context stored under the clean URL and served to subsequent visitors.
|
1.5.1 |
CVE6.5
NVDPending
|
| Aug 26, 2026 |
CVE-2026-19760
WP Fastest Cache permits Host-header cache poisoning and stored XSS
WP Fastest Cache through 1.5.0 writes an untrusted HTTP Host value into cached script source URLs when Polylang or Polylang Pro is active and Combine JS is enabled. An unauthenticated attacker can poison the shared page cache so attacker-controlled JavaScript executes for subsequent visitors.
|
1.5.1 |
CVE7.2
NVDPending
|
| Aug 25, 2026 |
CVE-2026-74932
WP Fastest Cache permits unauthenticated cache poisoning and cross-site scripting
WP Fastest Cache before 1.5.1 uses the unvalidated Host header to construct embedded asset URLs and omits that header from its cache key. An unauthenticated attacker can therefore cause a cached page to reference JavaScript on an attacker-controlled server; subsequent visitors receive the poisoned page and execute that script in the site's origin.
|
1.5.1 |
CVE7.5
NVDPending
|
| Nov 27, 2025 |
CVE-2025-10476
WP Fastest Cache: A security weakness
WP Fastest Cache is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 16, 2024 |
CVE-2020-36836
WP Fastest Cache: Arbitrary file deletion
WP Fastest Cache is affected by arbitrary file deletion. Exposure depends on how the affected operation is made reachable by the site. A successful request can remove files outside the intended scope and may make the site unavailable.
|
See mitigation notes |
CVE8.0
NVD8.1
|
| May 23, 2024 |
CVE-2024-4347
WP Fastest Cache: Filesystem traversal
WP Fastest Cache is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Jan 16, 2024 |
CVE-2021-24870
WP Fastest Cache: Cross-site scripting
WP Fastest Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jan 16, 2024 |
CVE-2021-24869
WP Fastest Cache: SQL injection
WP Fastest Cache is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Dec 04, 2023 |
CVE-2023-6063
WP Fastest Cache: SQL injection
WP Fastest Cache is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Jun 09, 2023 |
CVE-2023-1375
WP Fastest Cache: A security weakness
WP Fastest Cache is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| May 30, 2023 |
CVE-2023-1938
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Apr 06, 2023 |
CVE-2023-1931
WP Fastest Cache: A security weakness
WP Fastest Cache is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 06, 2023 |
CVE-2023-1930
WP Fastest Cache: A security weakness
WP Fastest Cache is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 06, 2023 |
CVE-2023-1929
WP Fastest Cache: A security weakness
WP Fastest Cache is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 06, 2023 |
CVE-2023-1928
WP Fastest Cache: A security weakness
WP Fastest Cache is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 06, 2023 |
CVE-2023-1927
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 06, 2023 |
CVE-2023-1926
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 06, 2023 |
CVE-2023-1925
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 06, 2023 |
CVE-2023-1924
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 06, 2023 |
CVE-2023-1923
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 06, 2023 |
CVE-2023-1922
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 06, 2023 |
CVE-2023-1921
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 06, 2023 |
CVE-2023-1920
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 06, 2023 |
CVE-2023-1919
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 06, 2023 |
CVE-2023-1918
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 27, 2021 |
CVE-2021-20714
Wp Fastest Cache: Filesystem traversal
Wp Fastest Cache is affected by filesystem traversal. Exploitation requires an authenticated administrator account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Aug 14, 2019 |
CVE-2015-9316
Wp Fastest Cache: SQL injection
Wp Fastest Cache is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD9.8
|
| Jul 30, 2019 |
CVE-2019-13635
Wp Fastest Cache: Filesystem traversal
Wp Fastest Cache is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVEPending
NVD9.1
|
| Jul 29, 2019 |
CVE-2019-6726
Wp Fastest Cache: Arbitrary file deletion
Wp Fastest Cache is affected by arbitrary file deletion. Exposure depends on how the affected operation is made reachable by the site. A successful request can remove files outside the intended scope and may make the site unavailable.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Apr 15, 2019 |
CVE-2018-17586
Wp Fastest Cache: Cross-site scripting
Wp Fastest Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Apr 15, 2019 |
CVE-2018-17585
Wp Fastest Cache: Cross-site scripting
Wp Fastest Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Apr 15, 2019 |
CVE-2018-17584
Wp Fastest Cache: Cross-site request forgery
Wp Fastest Cache is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Apr 15, 2019 |
CVE-2018-17583
Wp Fastest Cache: Cross-site scripting
Wp Fastest Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Sep 19, 2017 |
CVE-2015-4089
Wp Fastest Cache: Cross-site request forgery
Wp Fastest Cache is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD8.8
|