CVE · High

CVE-2023-1938 — WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 1.1.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-1938 WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] < 1.1.5 Cross-Site Request Forgery (CSRF) High 8.8 < 1.1.5 1.1.5 2023-05-02

CVE-2023-1938

The WP Fastest Cache plugin through version 1.1.4 contains a server-side request forgery vulnerability in the check_url function that allows administrators to send web requests to arbitrary destinations from the affected server. This flaw enables authenticated attackers with administrative access to interact with internal services and potentially read or alter their data. The vulnerable function is also susceptible to cross-site request forgery attacks, though this concern is secondary to the more serious SSRF issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.