WP Fastest Cache, CVE-2026-74916
- CVE, Research URL
- Home page URL
- Application
- Published on
- Sep 01, 2026
- Research Description
- The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored under, and served from, the clean URL's cache entry to every subsequent visitor.
- Affected versions
-
max 1.5.1.
- Status
-
vulnerable