CVE-2025-10583

LOW

WP Fastest Cache Premium <= 1.7.4 - Authenticated Server-Side Request Forgery via get_server_time_ajax_request

Title source: llm
STIX 2.1

Description

The WP Fastest Cache Premium plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.7.4 via the 'get_server_time_ajax_request' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The free version is not affected.

Scores

CVSS v3 3.5
EPSS 0.0020
EPSS Percentile 10.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
emrevona/WP Fastest Cache < 1.7.4
emrevona/WP Fastest Cache Premium < 1.7.4
Published Dec 12, 2025
Tracked Since Feb 18, 2026