Unauthorized Data Modification Vulnerability in WP Fastest Cache Plugin for WordPress
CVE-2025-10476
What is CVE-2025-10476?
The WP Fastest Cache plugin for WordPress is susceptible to unauthorized data modification due to a lack of capability checks in the wpfc_db_fix_callback() function. This issue impacts all versions up to and including 1.4.0. Authenticated attackers with Subscriber-level roles or higher can execute several database repair actions, particularly on sites with premium features activated. Such vulnerabilities expose sites to potential data manipulation and compromise, making it crucial for users to update and secure their installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Fastest Cache * <= 1.4.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved