Junglewise Threat Intelligence

CVE-2026-15350: WordPress The Cache Purger authorization bypass in audit log

CVE-2026-15350 · Severity: medium · CVSS 4.3 · Published 2026-07-16

Executive brief

The Cache Purger plugin for WordPress, which helps manage website performance by clearing cached data, contains a security flaw that allows low-level users to delete audit logs. An attacker with a basic account (such as a subscriber) can permanently erase the plugin's history of cache-clearing activities. This can hinder administrative oversight and destroy audit trails used for troubleshooting or security monitoring.

Technical details

The Cache Purger plugin for WordPress (up to version 2.3.20) is vulnerable to a missing authorization check (CWE-862) in its log-clearing functionality. The root cause is twofold: the plugin fails to verify administrative privileges before truncating the audit log (wp-content/purge.log), and it inadvertently exposes the required security nonce ('tcp_log_purge') in the admin bar on frontend pages visible to all authenticated users. An attacker with subscriber-level permissions can use this nonce to trigger the deletion of the audit history. A patch appears to be available in version 2.3.21 or via the latest changeset.

Affected products

  • kevp75 The Cache Purger up to, and including, 2.3.20

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References