SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-74916

MEDIUM · CVSS 6.5 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The WP Fastest Cache plugin for WordPress versions prior to 1.5.1 is vulnerable to a caching issue that allows unauthenticated attackers to manipulate cached pages by exploiting tracking-related query parameters. This could result in the delivery of malicious content to users accessing the cached pages, potentially leading to data exposure or phishing attacks. WordPress site administrators using this plugin should prioritize updating to version 1.5.1 or later to mitigate this risk.

CVE
CVE-2026-74916
Severity
MEDIUM
CVSS
6.5
EPSS
0.11%
WordPress

Original NVD Description

The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored under, and served from, the clean URL's cache entry to every subsequent visitor.