CVE-2020-36836

All FrameworksWordPressCWE-352CVE-2020-36836

CVE-2020-36836

State: PUBLISHED · Published: 2024-10-16 · Updated: 2026-04-08 · Assigner: Wordfence
Description
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2020/36xxx/CVE-2020-36836.json