CSRF
14 records40%First: 2015. Latest: 2023.
Plugin security history
The Wordfence Intelligence dataset currently contains 35 vulnerability records associated with WP Fastest Cache – WordPress Cache Plugin, published between 2015 and 2025.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2015 | 2 | |
| 2016 | 3 | |
| 2018 | 5 | |
| 2019 | 1 | |
| 2020 | 1 | |
| 2021 | 3 | |
| 2022 | 1 | |
| 2023 | 17 | |
| 2024 | 1 | |
| 2025 | 1 |
| Severity | Records | Share |
|---|---|---|
| Critical | 3 | 8.6% |
| High | 9 | 25.7% |
| Medium | 23 | 65.7% |
First: 2015. Latest: 2023.
First: 2016. Latest: 2025.
First: 2015. Latest: 2023.
First: 2019. Latest: 2024.
First: 2016. Latest: 2023.
First: 2018. Latest: 2018.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
1.4.11.2.71.2.21.1.51.1.30.8.9.10.9.50.9.1.70.9.0.30.8.9.60.8.8.60.8.7.50.8.6.00.8.5.80.8.4.90.8.3.5Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-1.4.0 | WP Fastest Cache <= 1.4.0 - Missing Authorization to Authenticated (Subscriber+) DB Cleanup Actions | November 26, 2025 | 1.4.1 | Medium |
*-1.2.6 | WP Fastest Cache <= 1.2.6 - Authenticated (Administrator+) Arbitrary File Deletion | May 10, 2024 | 1.2.7 | High |
*-1.2.1 | WP Fastest Cache <= 1.2.1 - Unauthenticated SQL Injection | November 13, 2023 | 1.2.2 | Critical |
*-1.1.4 | WP Fastest Cache <= 1.1.4 - Authenticated(Administrator+) Blind Server Side Request Forgery via check_url | May 2, 2023 | 1.1.5 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_purgecache_varnish_callback' | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_clear_cache_of_allsites_callback' | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'deleteCacheToolbar' | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Missing Authorization in 'deleteCssAndJsCacheToolbar' | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Missing Authorization to Cache Deletion | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_toolbar_save_settings_callback' | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_pause_cdn_integration_ajax_request_callback' | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_preload_single_callback' | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'deleteCssAndJsCacheToolbar' | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_remove_cdn_integration_ajax_request_callback' | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_purgecache_varnish_callback' | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_preload_single_callback' | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_start_cdn_integration_ajax_request_callback' | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_clear_cache_of_allsites_callback' | April 6, 2023 | 1.1.3 | Medium |
*-1.1.2 | WP Fastest Cache <= 1.1.2 - Cross-Site Request Forgery via 'wpfc_preload_single_save_settings_callback' | April 6, 2023 | 1.1.3 | Medium |
*-0.8.9.0 | WP Fastest Cache <= 0.8.9.0 - Directory Traversal to Arbitrary File Deletion | January 24, 2022 | 0.8.9.1 | Medium |
[*, 0.9.5) | WP Fastest Cache < 0.9.5 - Authenticated (Subscriber+) SQL Injection | October 14, 2021 | 0.9.5 | High |
[*, 0.9.5) | WP Fastest Cache < 0.9.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting | October 14, 2021 | 0.9.5 | High |
[*, 0.9.1.7) | WP Fastest Cache <= 0.9.1.6 - Authenticated (Admin+) Directory Traversal to Arbitrary File Deletion | April 27, 2021 | 0.9.1.7 | Medium |
[*, 0.9.0.3) | WP Fastest Cache <= 0.9.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion | February 5, 2020 | 0.9.0.3 | High |
*-0.8.9.5 | WP Fastest Cache <= 0.8.9.5 - Directory Traversal | July 28, 2019 | 0.8.9.6 | Critical |
Selected source records
Published: November 26, 2025
Published: May 10, 2024
Published: November 13, 2023
Published: May 2, 2023
Published: April 6, 2023
Published: April 6, 2023
Published: April 6, 2023
Published: April 6, 2023
Published: November 13, 2023
Published: November 11, 2015
Published: July 28, 2019
Published: October 14, 2021
Published: May 24, 2016
Published: October 9, 2018
Published: October 14, 2021
Published: May 26, 2015
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.