PT-2019-9508 · WordPress · Wp Fastest Cache

Mohammed Ansari S

·

Published

2019-04-15

·

Updated

2019-09-07

·

CVE-2018-17583

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Fastest Cache plugin version 0.8.8.5
Description The issue concerns a problem where an attacker can exploit the rules[0][content] parameter in a wpfc save exclude pages action to perform a cross-site scripting (XSS) attack.
Recommendations For WP Fastest Cache plugin version 0.8.8.5, avoid using the rules[0][content] parameter in the wpfc save exclude pages action until the issue is resolved. As a temporary workaround, consider restricting access to the wpfc save exclude pages action to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17583

Affected Products

Wp Fastest Cache