
Urgent WP Fastest Cache Security Update
A security update has been released for WP Fastest Cache, a popular WordPress caching plugin used on more than one million websites.
Website owners should update WP Fastest Cache to version 1.5.2 as soon as possible. Versions 1.5.0 and earlier contain two vulnerabilities that can potentially be exploited without an attacker having a WordPress account.
What Was Discovered?
The first vulnerability, identified as CVE-2026-74916, involves cache poisoning.
WP Fastest Cache could create a shared cached page from a request containing manipulated query-string parameters. That altered version could then be delivered to people visiting the normal website address.
This vulnerability affects WP Fastest Cache versions 0.8.7.7 through 1.5.0 and received a CVSS severity score of 6.1.
A second vulnerability, CVE-2026-19760, involves stored cross-site scripting, commonly called stored XSS.
Under certain configurations, an unauthenticated attacker could cause malicious JavaScript to be written into a website’s shared cache. That code could then execute when visitors or administrators opened the affected page.
This particular attack requires Polylang or Polylang Pro to be active while WP Fastest Cache’s Combine JS feature is enabled. It received a CVSS severity score of 7.2.
What Could an Attacker Do?
Depending on the website’s configuration and the vulnerability being exploited, an attacker could potentially:
- Display altered or fraudulent content
- Redirect visitors to another website
- Inject advertisements or SEO spam
- Capture information entered into an affected page
- Execute actions through a logged-in administrator’s browser
- Damage the website’s reputation or search visibility
These vulnerabilities do not automatically provide direct access to the server, database or hosting account. Receiving a vulnerability warning also does not mean that a website has already been compromised.
It does mean that affected installations should be updated promptly.
Which Versions Are Affected?
WP Fastest Cache 1.5.0 and earlier should be considered vulnerable.
Version 1.5.1 corrected the two publicly disclosed cache-poisoning and stored-XSS vulnerabilities. Version 1.5.2 includes those corrections along with additional security improvements and stronger permission checks for Varnish and page-specific cache-management functions.
As of September 14, 2026, website owners should update directly to version 1.5.2.
What Website Owners Should Do
Updating the plugin is only the first step. Because this vulnerability involves cached content, every applicable cache should also be purged.
Website owners and administrators should:
- Create or verify a current website backup.
- Update WP Fastest Cache to version 1.5.2.
- Select “Delete Cache and Minified CSS/JS” from WP Fastest Cache.
- Purge any Cloudflare, CDN, Varnish, proxy or hosting-level cache.
- Run a complete Wordfence or comparable security scan.
- Check the website for unfamiliar scripts, redirects, administrator accounts or modified files.
Clearing every cache layer helps ensure that content created before the update is not still being delivered to visitors.
Should You Assume Your Website Was Hacked?
No. A vulnerable plugin is not the same thing as a confirmed compromise.
If the plugin is updated, every cache is cleared, the website scans clean and there are no unexplained redirects, administrator accounts or file changes, there is generally no reason to assume a breach occurred.
If suspicious behavior is discovered, the website should be treated as a possible security incident and examined before normal operation continues.
Tarheel Media Can Help
Keeping WordPress software updated is an essential part of maintaining a secure website. A firewall such as Wordfence can help block malicious traffic, but it does not replace installing security updates.
If you are uncertain whether your website uses WP Fastest Cache, which version is installed or whether every cache layer has been cleared, contact Tarheel Media for assistance.
Additional technical information is available through the official WP Fastest Cache changelog, Wordfence’s cache-poisoning advisory and Wordfence’s stored-XSS advisory.

