WP Fastest Cache is a WordPress caching plugin that, despite a narrow product footprint, sits within the broadly deployed WordPress ecosystem and reaches a significant installed base across numerous websites. Vulnerabilities affecting the vendor cluster around common web-application weakness classes—cross-site request forgery, missing authorization controls, path traversal, cross-site scripting, and SQL injection—that reflect the plugin's role in handling user input, managing site configuration, and interacting with the underlying database. A meaningful share of the vendor's disclosures reach serious severity, and a moderate tendency toward public exploit availability has characterized this exposure. Because WordPress plugins operate with administrative privileges and direct access to site data, flaws in widely installed caching tools can pose material risk across thousands of instances. Defenders should prioritize keeping this plugin updated and restrict administrative access; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpfastestcache over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6063HIGH The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by u | Dec 4, 2023 | 7.5 | 82 | NO | YES |
CVE-2019-13635CRITICAL The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal. | Jul 30, 2019 | 9.1 | 52 | NO | NO |
CVE-2020-36836HIGH The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and i | Oct 16, 2024 | 8.1 | 35 | NO | YES |
CVE-2023-1938HIGH The WP Fastest Cache WordPress plugin before 1.1.5 does not have CSRF check in an AJAX action, and does not validate user input before using it in the wp_remote_get() function, lea | May 30, 2023 | 8.8 | 31 | NO | NO |
CVE-2018-17584HIGH The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page. | Apr 15, 2019 | 8.8 | 27 | NO | NO |
CVE-2021-24869HIGH The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading to an SQL injection expl | Jan 16, 2024 | 8.8 | 26 | NO | NO |
CVE-2015-9316CRITICAL The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter. | Aug 14, 2019 | 9.8 | 25 | NO | NO |
CVE-2021-20714MEDIUM Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administrator privileges to delete arbitrary files on the server via u | Apr 27, 2021 | 6.5 | 22 | NO | NO |
CVE-2018-17586MEDIUM The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pages action. | Apr 15, 2019 | 6.1 | 22 | NO | NO |
CVE-2018-17583MEDIUM The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action. | Apr 15, 2019 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpfastestcache.
Media articles that mention a CVE ID that affects a product developed by Wpfastestcache — matched by CVE ID, not by vendor name.