wpfastestcache records
29 published records for vendor wpfastestcache.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3.4%
- Pre-auth RCE
- 0
- With a fix record
- 13.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)14
- CWE-862 Missing Authorization5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
29 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2023-6063Weaponized | WP Fastest Cache < 1.2.2 - Unauthenticated SQL Injectionwpfastestcache · wp fastest cache · CWE-89 | High7.5 | — | 73.7% | Dec 4, 2023 |
49Plan | CVE-2019-13635No exploit | The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal.wpfastestcache · wp fastest cache · CWE-22 | Critical9.1 | — | 44.4% | Jul 30, 2019 |
40Plan | CVE-2015-9316No exploit | The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via twpfastestcache · wp fastest cache · CWE-89 | Critical9.8 | — | 3.0% | Aug 14, 2019 |
38Monitor | CVE-2023-1938No exploit | WP Fatest Cache < 1.1.5 - Blind SSRF via CSRFwpfastestcache · wp fastest cache · CWE-918 | High8.8 | — | 8.5% | May 30, 2023 |
35Monitor | CVE-2021-24869No exploit | WP Fastest Cache < 0.9.5 - Subscriber+ SQL Injectionwpfastestcache · wp fastest cache · CWE-89 | High8.8 | — | 1.2% | Jan 16, 2024 |
35Monitor | CVE-2015-4089No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin beforewpfastestcache · wp fastest cache · CWE-352 | High8.8 | — | 1.0% | Sep 19, 2017 |
35Monitor | CVE-2018-17584No exploit | The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.wpfastestcache · wp fastest cache · CWE-352 | High8.8 | — | 0.9% | Apr 15, 2019 |
32Monitor | CVE-2020-36836Proof of concept | WP Fastest Cache <= 0.9.0.2 - Authenticated (Subscriber+) Arbitrary File Deletionwpfastestcache · wp fastest cache · CWE-352 | High8.0 | — | 1.5% | Oct 16, 2024 |
27Monitor | CVE-2019-6726No exploit | The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_postratings_clear_faswpfastestcache · wp fastest cache · CWE-22 | Medium6.5 | — | 4.3% | Jul 29, 2019 |
27Monitor | CVE-2021-20714No exploit | Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administrator privileges to dewpfastestcache · wp fastest cache · CWE-22 | Medium6.5 | — | 2.6% | Apr 27, 2021 |
24Monitor | CVE-2018-17586No exploit | The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pages action.wpfastestcache · wp fastest cache · CWE-79 | Medium6.1 | — | 1.4% | Apr 15, 2019 |
24Monitor | CVE-2018-17585No exploit | The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or wpFastestCacheLanguawpfastestcache · wp fastest cache · CWE-79 | Medium6.1 | — | 1.4% | Apr 15, 2019 |
24Monitor | CVE-2018-17583No exploit | The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action.wpfastestcache · wp fastest cache · CWE-79 | Medium6.1 | — | 1.4% | Apr 15, 2019 |
24Monitor | CVE-2021-24870No exploit | WP Fastest Cache < 0.9.5 - CSRF to Stored Cross-Site Scriptingwpfastestcache · wp fastest cache · CWE-352 | Medium6.1 | — | 0.3% | Jan 16, 2024 |
17Monitor | CVE-2023-1375No exploit | WP Fastest Cache <= 1.1.2 - Missing Authorization to Cache Deletionwpfastestcache · wp fastest cache · CWE-862 | Medium4.3 | — | 0.5% | Jun 9, 2023 |
17Monitor | CVE-2023-1928No exploit | WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_preload_single_callback'wpfastestcache · wp fastest cache · CWE-862 | Medium4.3 | — | 0.4% | Apr 6, 2023 |
17Monitor | CVE-2023-1929No exploit | WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_purgecache_varnish_callback'wpfastestcache · wp fastest cache · CWE-862 | Medium4.3 | — | 0.4% | Apr 6, 2023 |
17Monitor | CVE-2023-1930No exploit | WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_clear_cache_of_allsites_callback'wpfastestcache · wp fastest cache · CWE-862 | Medium4.3 | — | 0.4% | Apr 6, 2023 |
17Monitor | CVE-2023-1931No exploit | WP Fastest Cache <= 1.1.2 - Missing Authorization in 'deleteCssAndJsCacheToolbar'wpfastestcache · wp fastest cache · CWE-862 | Medium4.3 | — | 0.4% | Apr 6, 2023 |
17Monitor | CVE-2023-1924No exploit | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_toolbar_save_settings_callback'wpfastestcache · wp fastest cache · CWE-352 | Medium4.3 | — | 0.2% | Apr 6, 2023 |
17Monitor | CVE-2023-1925No exploit | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_clear_cache_of_allsites_callback'wpfastestcache · wp fastest cache · CWE-352 | Medium4.3 | — | 0.2% | Apr 6, 2023 |
17Monitor | CVE-2023-1918No exploit | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_preload_single_callback'wpfastestcache · wp fastest cache · CWE-352 | Medium4.3 | — | 0.2% | Apr 6, 2023 |
17Monitor | CVE-2023-1927No exploit | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'deleteCssAndJsCacheToolbar'wpfastestcache · wp fastest cache · CWE-352 | Medium4.3 | — | 0.2% | Apr 6, 2023 |
17Monitor | CVE-2023-1926No exploit | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'deleteCacheToolbar'wpfastestcache · wp fastest cache · CWE-352 | Medium4.3 | — | 0.2% | Apr 6, 2023 |
17Monitor | CVE-2023-1919No exploit | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_preload_single_save_settings_callback'wpfastestcache · wp fastest cache · CWE-352 | Medium4.3 | — | 0.2% | Apr 6, 2023 |
- CVE-2023-606352Plan
WP Fastest Cache < 1.2.2 - Unauthenticated SQL Injection
HighCVSS 7.5WeaponizedEPSS 74%wpfastestcache · wp fastest cacheDec 4, 2023
- CVE-2019-1363549Plan
The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal.
CriticalCVSS 9.1No exploitEPSS 44%wpfastestcache · wp fastest cacheJul 30, 2019
- CVE-2015-931640Plan
The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via t
CriticalCVSS 9.8No exploitEPSS 3%wpfastestcache · wp fastest cacheAug 14, 2019
- CVE-2023-193838Monitor
WP Fatest Cache < 1.1.5 - Blind SSRF via CSRF
HighCVSS 8.8No exploitEPSS 8%wpfastestcache · wp fastest cacheMay 30, 2023
- CVE-2021-2486935Monitor
WP Fastest Cache < 0.9.5 - Subscriber+ SQL Injection
HighCVSS 8.8No exploitEPSS 1%wpfastestcache · wp fastest cacheJan 16, 2024
- CVE-2015-408935Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin before
HighCVSS 8.8No exploitEPSS 1%wpfastestcache · wp fastest cacheSep 19, 2017
- CVE-2018-1758435Monitor
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.
HighCVSS 8.8No exploitEPSS 1%wpfastestcache · wp fastest cacheApr 15, 2019
- CVE-2020-3683632Monitor
WP Fastest Cache <= 0.9.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion
HighCVSS 8.0Proof of conceptEPSS 1%wpfastestcache · wp fastest cacheOct 16, 2024
- CVE-2019-672627Monitor
The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_postratings_clear_fas
MediumCVSS 6.5No exploitEPSS 4%wpfastestcache · wp fastest cacheJul 29, 2019
- CVE-2021-2071427Monitor
Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administrator privileges to de
MediumCVSS 6.5No exploitEPSS 3%wpfastestcache · wp fastest cacheApr 27, 2021
- CVE-2018-1758624Monitor
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pages action.
MediumCVSS 6.1No exploitEPSS 1%wpfastestcache · wp fastest cacheApr 15, 2019
- CVE-2018-1758524Monitor
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or wpFastestCacheLangua
MediumCVSS 6.1No exploitEPSS 1%wpfastestcache · wp fastest cacheApr 15, 2019
- CVE-2018-1758324Monitor
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action.
MediumCVSS 6.1No exploitEPSS 1%wpfastestcache · wp fastest cacheApr 15, 2019
- CVE-2021-2487024Monitor
WP Fastest Cache < 0.9.5 - CSRF to Stored Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%wpfastestcache · wp fastest cacheJan 16, 2024
- CVE-2023-137517Monitor
WP Fastest Cache <= 1.1.2 - Missing Authorization to Cache Deletion
MediumCVSS 4.3No exploitEPSS 1%wpfastestcache · wp fastest cacheJun 9, 2023
- CVE-2023-192817Monitor
WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_preload_single_callback'
MediumCVSS 4.3No exploitEPSS 0%wpfastestcache · wp fastest cacheApr 6, 2023
- CVE-2023-192917Monitor
WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_purgecache_varnish_callback'
MediumCVSS 4.3No exploitEPSS 0%wpfastestcache · wp fastest cacheApr 6, 2023
- CVE-2023-193017Monitor
WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_clear_cache_of_allsites_callback'
MediumCVSS 4.3No exploitEPSS 0%wpfastestcache · wp fastest cacheApr 6, 2023
- CVE-2023-193117Monitor
WP Fastest Cache <= 1.1.2 - Missing Authorization in 'deleteCssAndJsCacheToolbar'
MediumCVSS 4.3No exploitEPSS 0%wpfastestcache · wp fastest cacheApr 6, 2023
- CVE-2023-192417Monitor
WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_toolbar_save_settings_callback'
MediumCVSS 4.3No exploitEPSS 0%wpfastestcache · wp fastest cacheApr 6, 2023
- CVE-2023-192517Monitor
WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_clear_cache_of_allsites_callback'
MediumCVSS 4.3No exploitEPSS 0%wpfastestcache · wp fastest cacheApr 6, 2023
- CVE-2023-191817Monitor
WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_preload_single_callback'
MediumCVSS 4.3No exploitEPSS 0%wpfastestcache · wp fastest cacheApr 6, 2023
- CVE-2023-192717Monitor
WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'deleteCssAndJsCacheToolbar'
MediumCVSS 4.3No exploitEPSS 0%wpfastestcache · wp fastest cacheApr 6, 2023
- CVE-2023-192617Monitor
WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'deleteCacheToolbar'
MediumCVSS 4.3No exploitEPSS 0%wpfastestcache · wp fastest cacheApr 6, 2023
- CVE-2023-191917Monitor
WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_preload_single_save_settings_callback'
MediumCVSS 4.3No exploitEPSS 0%wpfastestcache · wp fastest cacheApr 6, 2023