CVE · Medium

CVE-2023-1919 — WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 1.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-1919, CVE-2023-1920, CVE-2023-1921, CVE-2023-1923, CVE-2023-1924, CVE-2023-1925, CVE-2023-1926, CVE-2023-1927 WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 1.1.3 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.1.3 1.1.3 2023-04-06

CVE-2023-1919, CVE-2023-1920, CVE-2023-1921, CVE-2023-1923, CVE-2023-1924, CVE-2023-1925, CVE-2023-1926, CVE-2023-1927

The WP Fastest Cache plugin through version 1.1.2 contains a cross-site request forgery vulnerability stemming from inadequate nonce verification in the wpfc_preload_single_save_settings_callback function. An unauthenticated attacker can exploit this flaw to modify cache settings if they successfully convince a site administrator to click a malicious link. The vulnerability was patched in version 1.1.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.