cleantalk
Vulnerabilities and Security Researches

WP Fastest Cache, CVE-2023-1375

CVE, Research URL

CVE-2023-1375

Application

WP Fastest Cache

Published on
Jun 09, 2023
Research Description
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized cache deletion in versions up to, and including, 1.1.2 due to a missing capability check in the deleteCacheToolbar function . This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the site's cache.
Affected versions
max 0.9.0.3.
Status
vulnerable