Executive brief
WP Fastest Cache is a popular WordPress caching plugin that improves website performance. The plugin fails to properly sanitize HTTP Host headers, allowing attackers to inject malicious scripts into cached pages. When combined with the Polylang plugin and certain settings, these scripts execute for all visitors who access the injected page, potentially compromising user sessions, stealing credentials, or spreading malware.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in WP Fastest Cache versions up to 1.5.0 caused by insufficient input sanitization and output escaping of the HTTP Host header. The vulnerability exists in the JS utilities component and is triggered when the Polylang or Polylang Pro plugin is active and the Combine JS option is enabled—these conditions cause the plugin to write unsanitized Host-header values into script src attributes within shared page-cache files. An unauthenticated attacker can craft a malicious request with a modified Host header, causing arbitrary JavaScript to be stored in the cache and executed in the browsers of all subsequent visitors. The vulnerability requires no user interaction beyond normal site access and affects all versions through 1.5.0.
Affected products
- Automattic WP Fastest Cache up to and including 1.5.0
Timeline
- 2026-08-26: disclosed