QID 150671

Date Published: 2023-04-17

QID 150671: WordPress WP Fastest Cache Plugin: Prior to 1.1.2 Multiple Security Vulnerabilities

WP Fastest Cache is a WordPress plugin. Its not only a wp cache plugin but also a speed optimization WordPress cache plugin.

WP Fastest Cache contains multiple vulnerabilities:
CVE-2023-1918 : Cross-Site Request Forgery via 'wpfc_preload_single_callback'
CVE-2023-1919 : Cross-Site Request Forgery via 'wpfc_preload_single_save_settings_callback'
CVE-2023-1920 : Cross-Site Request Forgery via 'wpfc_purgecache_varnish_callback'
CVE-2023-1921 : Cross-Site Request Forgery via 'wpfc_start_cdn_integration_ajax_request_callback'
CVE-2023-1922 : Cross-Site Request Forgery via 'wpfc_pause_cdn_integration_ajax_request_callback'
CVE-2023-1923 : Cross-Site Request Forgery via 'wpfc_remove_cdn_integration_ajax_request_callback'
CVE-2023-1924 : Cross-Site Request Forgery via 'wpfc_toolbar_save_settings_callback'
CVE-2023-1925 : Cross-Site Request Forgery via 'wpfc_clear_cache_of_allsites_callback'
CVE-2023-1926 : Cross-Site Request Forgery via 'deleteCacheToolbar'
CVE-2023-1927 : Cross-Site Request Forgery via 'deleteCssAndJsCacheToolbar'
CVE-2023-1928 : Missing Authorization in 'wpfc_preload_single_callback'
CVE-2023-1929 : Missing Authorization in 'wpfc_purgecache_varnish_callback'
CVE-2023-1930 : Missing Authorization in 'wpfc_clear_cache_of_allsites_callback'
CVE-2023-1931 : Missing Authorization in 'deleteCssAndJsCacheToolbar'

Affected Versions:
WP Fastest Cache versions up to and including 1.1.2

QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Customers are advised to upgrade to WP Fastest Cache 1.1.3 or later version to remediate this vulnerability.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    WP Fastest Cache URL Logo wordpress.org/plugins/wp-fastest-cache/