cleantalk
Vulnerabilities and Security Researches

WP Fastest Cache, 1fb5a8a0-4769-4e1a-9119-a63afd9364cc

Application

WP Fastest Cache

Published on
-
Research Description
WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 0.9.0.3 WP Fastest Cache &lt; 0.9.0.3 - Cross-Site Request Forgery (CSRF) Arbitrary File Deletion The plugin did not have a CSRF nonce check on the &quot;wpfc_delete_current_page_cache&quot; action, allowing CSRF attacks against authenticated users to delete arbitrary files, including the wp-config.php file.
Affected versions
max 0.9.0.3.
Status
vulnerable