Unauthorized File Deletion Vulnerability in WP Fastest Cache
CVE-2020-36836
8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 October 2024
What is CVE-2020-36836?
The WP Fastest Cache plugin for WordPress is susceptible to a security flaw that permits authenticated users with minimal permissions to delete arbitrary files from the server. This vulnerability arises from inadequate capability checks and insufficient validation of file paths. Consequently, it poses a significant risk to the integrity of the server and its files, allowing potential exploitation by users with low-level access.
Affected Version(s)
WP Fastest Cache β WordPress Cache Plugin 0 < 0.9.0.3