CVE · Medium

CVE-2023-1928 — WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 1.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-1928 WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 1.1.3 Missing Authorization Medium 4.3 < 1.1.3 1.1.3 2023-04-06

CVE-2023-1928

The WP Fastest Cache plugin in versions 1.1.2 and earlier fails to validate user permissions on the wpfc_preload_single_callback function, allowing subscribers and other low-privileged authenticated users to trigger cache preloading operations. An attacker with a basic user account could exploit this missing capability check to initiate cache creation without proper authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.