CVE · Medium

CVE-2023-1924 — WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 1.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-1919, CVE-2023-1920, CVE-2023-1921, CVE-2023-1923, CVE-2023-1924, CVE-2023-1925, CVE-2023-1926, CVE-2023-1927 WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 1.1.3 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.1.3 1.1.3 2023-04-06

CVE-2023-1919, CVE-2023-1920, CVE-2023-1921, CVE-2023-1923, CVE-2023-1924, CVE-2023-1925, CVE-2023-1926, CVE-2023-1927

The WP Fastest Cache plugin through version 1.1.2 contains a cross-site request forgery vulnerability in the wpfc_preload_single_save_settings_callback function due to inadequate nonce verification. An attacker could exploit this flaw by crafting a malicious request that, when clicked by an administrator, would allow the attacker to modify cache settings without proper authorization. The vulnerability affects all installations running the vulnerable versions of the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.