Description
WordPress Plugin WP Fastest Cache is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to delete arbitrary files in the context of the webserver process. WordPress Plugin WP Fastest Cache version 0.8.9.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.8.9.1 or latest
References
https://0day.work/cve-2019-6726-arbitrary-file-deletion-in-wp-fastest-cache-0-8-8-1/
https://plugins.svn.wordpress.org/wp-fastest-cache/trunk/readme.txt
Related Vulnerabilities
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6335)
WordPress Plugin GA Top post for WP by Asentechllc Security Bypass (1.0)
WordPress Plugin WP e-Commerce Shop Styling Remote File Inclusion (1.7.2)
WordPress Plugin Advanced Woo Search Unspecified Vulnerability (1.69)