← volver
CVE-2024-4347highCWE-22

WP Fastest Cache <= 1.2.6 - Authenticated (Administrator+) Arbitrary File Deletion

21Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 7.2epss 0.9%
probabilidad de explotación
0.9%top 42% de las CVE
explotación observada
noninguna fuente lo reporta
The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the specificDeleteCache function. This makes it possible for authenticated attackers to delete arbitrary files on the server, which can include wp-config.php files of the affected site or other sites in a shared hosting environment.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H