PT-2024-10846 · WordPress · Wp Fastest Cache

·

CVE-2020-36836

·

Published

2024-10-15

·

Updated

2025-09-18

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Fastest Cache versions up to 0.9.0.2
Description The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.
Recommendations For versions up to 0.9.0.2, update to the latest version to mitigate the risk of arbitrary file deletion. As a temporary workaround, consider restricting access to sensitive files and directories on the server until the update is applied.

Exploit

Fix

Path traversal

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36836

Affected Products

Wp Fastest Cache