QID 150671
Date Published: 2023-04-17
QID 150671: WordPress WP Fastest Cache Plugin: Prior to 1.1.2 Multiple Security Vulnerabilities
WP Fastest Cache is a WordPress plugin. Its not only a wp cache plugin but also a speed optimization WordPress cache plugin.
WP Fastest Cache contains multiple vulnerabilities:
CVE-2023-1918 : Cross-Site Request Forgery via 'wpfc_preload_single_callback'
CVE-2023-1919 : Cross-Site Request Forgery via 'wpfc_preload_single_save_settings_callback'
CVE-2023-1920 : Cross-Site Request Forgery via 'wpfc_purgecache_varnish_callback'
CVE-2023-1921 : Cross-Site Request Forgery via 'wpfc_start_cdn_integration_ajax_request_callback'
CVE-2023-1922 : Cross-Site Request Forgery via 'wpfc_pause_cdn_integration_ajax_request_callback'
CVE-2023-1923 : Cross-Site Request Forgery via 'wpfc_remove_cdn_integration_ajax_request_callback'
CVE-2023-1924 : Cross-Site Request Forgery via 'wpfc_toolbar_save_settings_callback'
CVE-2023-1925 : Cross-Site Request Forgery via 'wpfc_clear_cache_of_allsites_callback'
CVE-2023-1926 : Cross-Site Request Forgery via 'deleteCacheToolbar'
CVE-2023-1927 : Cross-Site Request Forgery via 'deleteCssAndJsCacheToolbar'
CVE-2023-1928 : Missing Authorization in 'wpfc_preload_single_callback'
CVE-2023-1929 : Missing Authorization in 'wpfc_purgecache_varnish_callback'
CVE-2023-1930 : Missing Authorization in 'wpfc_clear_cache_of_allsites_callback'
CVE-2023-1931 : Missing Authorization in 'deleteCssAndJsCacheToolbar'
Affected Versions:
WP Fastest Cache versions up to and including 1.1.2
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
- WP Fastest Cache -
wordpress.org/plugins/wp-fastest-cache/
CVEs related to QID 150671
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WP Fastest Cache |
|