PT-2019-9510 · WordPress · Wp Fastest Cache

Published

2019-04-15

·

Updated

2019-09-07

·

CVE-2018-17585

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Fastest Cache plugin version 0.8.8.5
Description The issue concerns a problem with the WP Fastest Cache plugin for WordPress, where there is a potential for XSS via the wpFastestCachePreload number or wpFastestCacheLanguage parameter in the wpfastestcacheoptions.
Recommendations For WP Fastest Cache plugin version 0.8.8.5, consider updating to a newer version that addresses this issue, as using outdated versions may pose a risk. Avoid using the wpFastestCachePreload number or wpFastestCacheLanguage parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17585

Affected Products

Wp Fastest Cache