WordPress Plugin Vulnerabilities

WP Fastest Cache 0.8.7.7 - 1.5.0 - Unauthenticated Cache Poisoning via Unkeyed Tracking Parameters

Description

The plugin does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored under, and served from, the clean URL's cache entry to every subsequent visitor.

Where another component on the site reflects one of those parameters into the page, this results in stored Cross-Site Scripting affecting every visitor of the poisoned URL.

Proof of Concept

Affects Plugins

Fixed in 1.5.1

References

Classification

Type
CACHE POISONING

Miscellaneous

Original Researcher
Amity Gilmour
Submitter
Amity Gilmour
Verified
Yes

Timeline

Publicly Published
2026-08-26 (about 5 days ago)
Added
2026-08-26 (about 5 days ago)
Last Updated
2026-08-26 (about 5 days ago)

Other