← WordPress Vulnerabilities
WordPress security by component

Wp Fastest Cache

Wp Fastest Cache improves WordPress page delivery by creating cached versions of pages and providing cache management settings.

Wp Fastest Cache (wp-fastest-cache) is a WordPress plugin with 34 published CVE records in this archive. The latest tracked vulnerability was published Sep 01, 2026; the highest published CVSS base score is 9.8.

Plugin slug: wp-fastest-cache

CVE-2026-74916: WP Fastest Cache permits unauthenticated web-cache poisoning

WP Fastest Cache before 1.5.1 caches pages requested with certain tracking query parameters without incorporating those parameters into the cache key. An unauthenticated attacker can have a page rendered in the attacker's request context stored under the clean URL and served to subsequent visitors.

PublishedSep 01, 2026
Known safe version1.5.1
Published vulnerabilities for wp-fastest-cache
Safe version
Sep 01, 2026 CVE-2026-74916
WP Fastest Cache permits unauthenticated web-cache poisoning
WP Fastest Cache before 1.5.1 caches pages requested with certain tracking query parameters without incorporating those parameters into the cache key. An unauthenticated attacker can have a page rendered in the attacker's request context stored under the clean URL and served to subsequent visitors.
1.5.1
CVE6.5
NVDPending
Aug 26, 2026 CVE-2026-19760
WP Fastest Cache permits Host-header cache poisoning and stored XSS
WP Fastest Cache through 1.5.0 writes an untrusted HTTP Host value into cached script source URLs when Polylang or Polylang Pro is active and Combine JS is enabled. An unauthenticated attacker can poison the shared page cache so attacker-controlled JavaScript executes for subsequent visitors.
1.5.1
CVE7.2
NVDPending
Aug 25, 2026 CVE-2026-74932
WP Fastest Cache permits unauthenticated cache poisoning and cross-site scripting
WP Fastest Cache before 1.5.1 uses the unvalidated Host header to construct embedded asset URLs and omits that header from its cache key. An unauthenticated attacker can therefore cause a cached page to reference JavaScript on an attacker-controlled server; subsequent visitors receive the poisoned page and execute that script in the site's origin.
1.5.1
CVE7.5
NVDPending
Nov 27, 2025 CVE-2025-10476
WP Fastest Cache: A security weakness
WP Fastest Cache is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Oct 16, 2024 CVE-2020-36836
WP Fastest Cache: Arbitrary file deletion
WP Fastest Cache is affected by arbitrary file deletion. Exposure depends on how the affected operation is made reachable by the site. A successful request can remove files outside the intended scope and may make the site unavailable.
See mitigation notes
CVE8.0
NVD8.1
May 23, 2024 CVE-2024-4347
WP Fastest Cache: Filesystem traversal
WP Fastest Cache is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.2
NVDPending
Jan 16, 2024 CVE-2021-24870
WP Fastest Cache: Cross-site scripting
WP Fastest Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jan 16, 2024 CVE-2021-24869
WP Fastest Cache: SQL injection
WP Fastest Cache is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Dec 04, 2023 CVE-2023-6063
WP Fastest Cache: SQL injection
WP Fastest Cache is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD7.5
Jun 09, 2023 CVE-2023-1375
WP Fastest Cache: A security weakness
WP Fastest Cache is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
May 30, 2023 CVE-2023-1938
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8
Apr 06, 2023 CVE-2023-1931
WP Fastest Cache: A security weakness
WP Fastest Cache is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Apr 06, 2023 CVE-2023-1930
WP Fastest Cache: A security weakness
WP Fastest Cache is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Apr 06, 2023 CVE-2023-1929
WP Fastest Cache: A security weakness
WP Fastest Cache is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Apr 06, 2023 CVE-2023-1928
WP Fastest Cache: A security weakness
WP Fastest Cache is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Apr 06, 2023 CVE-2023-1927
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Apr 06, 2023 CVE-2023-1926
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Apr 06, 2023 CVE-2023-1925
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Apr 06, 2023 CVE-2023-1924
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Apr 06, 2023 CVE-2023-1923
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Apr 06, 2023 CVE-2023-1922
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Apr 06, 2023 CVE-2023-1921
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Apr 06, 2023 CVE-2023-1920
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Apr 06, 2023 CVE-2023-1919
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Apr 06, 2023 CVE-2023-1918
WP Fastest Cache: Cross-site request forgery
WP Fastest Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Apr 27, 2021 CVE-2021-20714
Wp Fastest Cache: Filesystem traversal
Wp Fastest Cache is affected by filesystem traversal. Exploitation requires an authenticated administrator account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVEPending
NVD6.5
Aug 14, 2019 CVE-2015-9316
Wp Fastest Cache: SQL injection
Wp Fastest Cache is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD9.8
Jul 30, 2019 CVE-2019-13635
Wp Fastest Cache: Filesystem traversal
Wp Fastest Cache is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVEPending
NVD9.1
Jul 29, 2019 CVE-2019-6726
Wp Fastest Cache: Arbitrary file deletion
Wp Fastest Cache is affected by arbitrary file deletion. Exposure depends on how the affected operation is made reachable by the site. A successful request can remove files outside the intended scope and may make the site unavailable.
See mitigation notes
CVEPending
NVD6.5
Apr 15, 2019 CVE-2018-17586
Wp Fastest Cache: Cross-site scripting
Wp Fastest Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Apr 15, 2019 CVE-2018-17585
Wp Fastest Cache: Cross-site scripting
Wp Fastest Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Apr 15, 2019 CVE-2018-17584
Wp Fastest Cache: Cross-site request forgery
Wp Fastest Cache is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD8.8
Apr 15, 2019 CVE-2018-17583
Wp Fastest Cache: Cross-site scripting
Wp Fastest Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Sep 19, 2017 CVE-2015-4089
Wp Fastest Cache: Cross-site request forgery
Wp Fastest Cache is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD8.8