Unauthorized Data Modification Vulnerability in WP Fastest Cache Plugin for WordPress
CVE-2025-10476
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 November 2025
What is CVE-2025-10476?
The WP Fastest Cache plugin for WordPress is susceptible to unauthorized data modification due to a lack of capability checks in the wpfc_db_fix_callback() function. This issue impacts all versions up to and including 1.4.0. Authenticated attackers with Subscriber-level roles or higher can execute several database repair actions, particularly on sites with premium features activated. Such vulnerabilities expose sites to potential data manipulation and compromise, making it crucial for users to update and secure their installations.
Affected Version(s)
WP Fastest Cache β WordPress Cache Plugin 0 <= 1.4.0