CVE-2020-36836 describes an arbitrary file deletion vulnerability in the WP Fastest Cache plugin for WordPress, affecting versions up to and including 0.9.0.2. This flaw, stemming from insufficient capability checks and path validation, allows authenticated users with minimal permissions to delete arbitrary files on the server. Rated as HIGH severity (CVSS 8.1), it presents a low-complexity attack vector with significant potential impact on data integrity and availability. While not actively exploited in the wild or on the KEV catalog, public exploit intelligence includes Nuclei templates, but there is no evidence of Metasploit modules, ExploitDB entries, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.0.3CPE matchmatch criteria | cpe:2.3:a:wpfastestcache:wp_fastest_cache:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.