CVE-2026-74916
Received Received - Intake

WP Fastest Cache Page Cache Key Bypass

Vulnerability report for CVE-2026-74916, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: WPScan

Description

The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored under, and served from, the clean URL's cache entry to every subsequent visitor.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wp_fastest_cache wp_f fastest_cache to 1.5.1 (exc)
wp_fastest_cache wp_f fastest_cache From 0.8.7.7 (inc) to 1.5.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated cache poisoning issue in the WP Fastest Cache WordPress plugin affecting versions 0.8.7.7 through 1.5.0. The plugin fails to include tracking-related query parameters in its page-cache key, causing pages requested with these parameters to still be cached. Attackers can exploit this by having a page rendered under their own context stored under a clean URL's cache entry, which is then served to all subsequent visitors.

Detection Guidance

Check if you are running WP Fastest Cache versions 0.8.7.7 through 1.5.0. Inspect cached pages for unexpected query parameters or content changes. Monitor server logs for unusual caching behavior or repeated requests with tracking parameters.

Impact Analysis

If another site component reflects these tracking parameters into the page, it can result in stored Cross-Site Scripting (XSS) affecting every visitor of the poisoned URL. This means attackers could inject malicious scripts that run for all users visiting the affected page.

Mitigation Strategies

Update WP Fastest Cache to version 1.5.1 or later immediately. Disable caching temporarily if an update is not immediately possible. Review cached pages to identify any potential cache poisoning and clear affected caches.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74916. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart