CVE Database /
CVE-2020-36836
CVE · High
CVE-2020-36836 — WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 0.9.0.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-36836
|
WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 0.9.0.3 |
Cross-Site Request Forgery (CSRF) |
High
8.0
|
< 0.9.0.3
|
0.9.0.3 |
2020-02-05 |
—
|
CVE-2020-36836
The WP Fastest Cache plugin through version 0.9.0.2 contains a flaw that allows logged-in users with basic permissions to remove arbitrary files from the server. The vulnerability stems from inadequate permission verification and weak validation of file paths, enabling authenticated attackers with limited access to exploit the deletion functionality and remove files they should not be able to access.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings