S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Sep 8, 2025

CVE-2020-36836 Scanner

CVE-2020-36836 Scanner - Arbitrary File Deletion vulnerability in WordPress WP Fastest Cache

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-36836
8.0
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
WP Fastest Cache – WordPress Cache Pluginby emrevona
AFFECTED< 0.9.0.3SAFE ✓≥ 0.9.0.3
wp_fastest_cacheby wpfastestcache
AFFECTED< 0.9.0.3SAFE ✓≥ 0.9.0.3
Updated Aug 21, 2026View on NVD →
Detail

The WP Fastest Cache plugin is a popular caching solution used by WordPress website administrators to enhance the speed and performance of their sites. It is widely utilized due to its simplicity and effectiveness in reducing server load and improving user experience. The plugin is developed to automatically generate static HTML files from dynamic WordPress content. Site managers and developers often rely on it to decrease loading times for visitors, especially for high-traffic websites. By leveraging caching mechanisms, this plugin helps in decreasing the time to deliver pages to users, which can be critical in maintaining user engagement and search engine optimization. It's a favored choice for WordPress users aiming for an easy-to-manage performance upgrade solution.

The Arbitrary File Deletion vulnerability in the WP Fastest Cache plugin allows authenticated users with minimal permissions to delete files on the server without proper authorization checks. This flaw is possible due to inadequate capability checking and insufficient path validation in the plugin's code. As a result, malicious users could exploit this vulnerability to affect server functionality or erase crucial site files. The vulnerability has been identified in versions up to 0.9.0.2. Organizations using this plugin must be aware and consider implementing necessary updates to mitigate associated risks. The implications of such a vulnerability can be severe, disrupting website operations.

Technical details of the vulnerability include a lack of proper validation on user capabilities and path traversal checks within the WP Fastest Cache plugin. The vulnerable parameter is identified in the 'wpfc_delete_current_page_cache' action, accessed via the 'admin-ajax.php' endpoint. Exploitation requires an authenticated user session, but the attacker does not need elevated privileges beyond basic user-level access. By manipulating requests, attackers can direct the plugin to delete arbitrary files on the server, which can impede the safe running of applications hosted there. The parameter handling does not adequately restrict actions to authorized users, thus permitting exploitative behaviors.

The possible effects of this vulnerability are diverse and hazardous, as malicious users can remove vital system files, potentially leading to partial or full service denial. It can also lead to prolonged downtime if critical files are deleted, requiring restoration from backups. The business impact can be significant, including loss of revenue from e-commerce sites or reputational damage. If attackers delete index or configuration files, it can also expose sensitive data due to configuration reset or non-execution of security rules. Recovering from such incidents typically entails further resource allocation towards security audits and implementation of stricter access controls.

REFERENCES

Solution Advice
  • Update WP Fastest Cache to version 0.9.0.3 or later to mitigate this vulnerability.
  • Implement strict permission settings for all user accounts, minimizing potential unauthorized actions.
  • Regularly update all plugins to their latest versions to address potential security issues promptly.
  • Conduct routine security audits to identify and rectify configuration weaknesses.
  • Utilize file integrity monitoring to detect unauthorized changes to the website's files.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-36836 Scanner - Arbitrary File Deletion vulnerability in WordPress WP Fastest Cache | S4E