CVE · High

CVE-2021-24869 — WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 0.9.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24869 WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 0.9.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 0.9.5 0.9.5 2021-10-14

CVE-2021-24869

The WP Fastest Cache plugin contains a SQL injection flaw in versions prior to 0.9.5 affecting the 'id' parameter. Attackers with subscriber-level or higher privileges can exploit inadequate input sanitization and unprepared database queries to inject malicious SQL commands. This vulnerability allows authenticated users to extract sensitive data from the WordPress database by modifying existing queries.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.