CVE · Medium

CVE-2023-1923 — WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 1.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-1919, CVE-2023-1920, CVE-2023-1921, CVE-2023-1923, CVE-2023-1924, CVE-2023-1925, CVE-2023-1926, CVE-2023-1927 WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 1.1.3 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.1.3 1.1.3 2023-04-06

CVE-2023-1919, CVE-2023-1920, CVE-2023-1921, CVE-2023-1923, CVE-2023-1924, CVE-2023-1925, CVE-2023-1926, CVE-2023-1927

The WP Fastest Cache plugin contains a Cross-Site Request Forgery vulnerability affecting versions up to 1.1.2, stemming from inadequate nonce verification in the wpfc_preload_single_save_settings_callback function. An attacker could exploit this flaw by crafting a malicious request that, if clicked by an administrator, would allow modification of the plugin's cache settings without proper authorization. The vulnerability was remedied in version 1.1.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.