Unauthorized Data Modification Vulnerability in WP Fastest Cache Plugin for WordPress
CVE-2025-10476
4.3MEDIUM
What is CVE-2025-10476?
The WP Fastest Cache plugin for WordPress is susceptible to unauthorized data modification due to a lack of capability checks in the wpfc_db_fix_callback() function. This issue impacts all versions up to and including 1.4.0. Authenticated attackers with Subscriber-level roles or higher can execute several database repair actions, particularly on sites with premium features activated. Such vulnerabilities expose sites to potential data manipulation and compromise, making it crucial for users to update and secure their installations.
Affected Version(s)
WP Fastest Cache * <= 1.4.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dmitrii Ignatyev