CVE · Medium

CVE-2023-1931 — WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 1.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-1931 WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 1.1.3 Missing Authorization Medium 4.3 < 1.1.3 1.1.3 2023-04-06

CVE-2023-1931

The WP Fastest Cache plugin contains a capability check vulnerability affecting version 1.1.2 and earlier that allows subscribers and other low-privilege authenticated users to delete cached CSS and JavaScript files. The deleteCssAndJsCacheToolbar function fails to properly validate user permissions before executing cache removal operations. This flaw enables any logged-in user to trigger unintended data loss by clearing the site's CSS and JavaScript cache. The vulnerability was remedied in version 1.1.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.