Extension WordPress
Vulnérabilités WP Fastest Cache – WordPress Cache Plugin, page 2
Cette page rassemble les failles publiées pour WP Fastest Cache – WordPress Cache Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Fastest Cache – WordPress Cache Plugin
35 fiches
WP Fastest Cache < 0.9.5 – Authenticated (Subscriber+) SQL Injection
The WP Fastest Cache plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions before 0.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
[*, 0.9.5)
0.9.5
14/10/2021
WP Fastest Cache < 0.9.5 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 0.9.5. This is due to missing or incorrect nonce validation on the wpfc_save_cdn_integration function. This makes it possible for unauthenticated attackers to…
[*, 0.9.5)
0.9.5
14/10/2021
WP Fastest Cache <= 0.9.1.6 – Authenticated (Admin+) Directory Traversal to Arbitrary File Deletion
Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administrator privileges to delete arbitrary files on the server via unspecified vectors.
[*, 0.9.1.7)
0.9.1.7
27/04/2021
WP Fastest Cache <= 0.9.0.2 – Authenticated (Subscriber+) Arbitrary File Deletion
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated…
[*, 0.9.0.3)
0.9.0.3
05/02/2020
WP Fastest Cache <= 0.8.9.5 – Directory Traversal
The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal.
*-0.8.9.5
0.8.9.6
28/07/2019
WP Fastest Cache <= 0.8.8.5 – Cross-Site Scripting via the rules[0][content] parameter in a wpfc_save_exclude_pages action
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action.
*-0.8.8.5
0.8.8.6
09/10/2018
WP Fastest Cache <= 0.8.8.5 – Cross-Site Scripting via wpFastestCachePage options, wpFastestCachePreload_number or wpFastestCacheLanguage parameter
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or wpFastestCacheLanguage parameter.
*-0.8.8.5
0.8.8.6
09/10/2018
WP Fastest Cache <= 0.8.8.5 – Cross-Site Scripting via rules[0][content] parameter
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pages action.
*-0.8.8.5
0.8.8.6
09/10/2018
WP Fastest Cache <= 0.8.8.5 – Cross-Site Request Forgery via page to wpfastestcacheoptions
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.
*-0.8.8.5
0.8.8.6
09/10/2018
WP Fastest Cache <= 0.8.7.4 – SQL Injection
The WP Fastest Cache plugin for WordPress is vulnerable to blind SQL Injection via the ‘$comment_id’ parameter in versions up to, and including, 0.8.7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-0.8.7.4
0.8.7.5
22/02/2018
WP Fastest Cache <= 0.8.5.9 – Local File Inclusion
The WP Fastest Cache plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.8.5.9 via the id POST parameter. This allows authenticated attackers to include and execute arbitrary files on the server,…
*-0.8.5.9
0.8.6.0
13/07/2016
WP Fastest Cache <= 0.8.5.7 – Local File Inclusion
The WP Fastest Cache plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.8.5.7 via the 'id' parameter. This allows authenticated attackers to include and execute arbitrary files on the server, allowing…
*-0.8.5.7
0.8.5.8
24/05/2016
WP Fastest Cache <= 0.8.5.7 – Missing Authorization
The WP Fastest Cache plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpfc_save_cdn_integration_ajax_request_callback() function in versions up to, and including, 0.8.5.7. This makes it possible for unauthorized attackers to redirect…
*-0.8.5.7
0.8.5.8
23/05/2016
WP Fastest Cache < 0.8.4.9 – SQL Injection
The WP Fastest Cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter.
[*, 0.8.4.9)
0.8.4.9
11/11/2015
WP Fastest Cache < 0.8.3.5 – Multiple Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin before 0.8.3.5 for WordPress allow remote attackers to hijack the authentication of unspecified victims for requests that call the (1) saveOption,…
[*, 0.8.3.5)
0.8.3.5
26/05/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.