WordPress WP Fastest Cache Plugin - Full Path Disclosure
WordPress plugin WP Fastest Cache internal file system path was disclosed through direct access to unprotected PHP files.
wp_fastest_cachePoC 已收录
CVSS—
共找到 3 条公开漏洞记录
WordPress plugin WP Fastest Cache internal file system path was disclosed through direct access to unprotected PHP files.
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.
The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.