PT-2024-10846 · WordPress · Wp Fastest Cache

Glyn Wintle

·

Published

2024-10-15

·

Updated

2025-09-18

·

CVE-2020-36836

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Fastest Cache versions up to 0.9.0.2
Description The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.
Recommendations For versions up to 0.9.0.2, update to the latest version to mitigate the risk of arbitrary file deletion. As a temporary workaround, consider restricting access to sensitive files and directories on the server until the update is applied.

Exploit

Fix

Path traversal

CSRF

Weakness Enumeration

Related Identifiers

CVE-2020-36836

Affected Products

Wp Fastest Cache