CVE-2021-24869
WordPress vulnerability analysis and mitigation

Overview

The WP Fastest Cache WordPress plugin before version 0.9.5 contains a SQL injection vulnerability (CVE-2021-24869) that affects the set_urls_with_terms method. The vulnerability allows low-privilege users, such as subscribers, to perform SQL injection attacks due to improper escaping of user input before its use in SQL statements (Jetpack Blog, WPScan).

Technical details

The vulnerability exists in the set_urls_with_terms method where user input is directly concatenated into SQL queries without proper sanitization. The issue is exploitable when the classic-editor plugin is installed and activated. The vulnerability received a CVSS v3.1 score of 8.8 (HIGH) and is classified under CWE-89 (SQL Injection) (Jetpack Blog, NVD).

Impact

If successfully exploited, attackers could gain access to privileged information from the affected site's database, including usernames and hashed passwords. The vulnerability could potentially compromise sensitive database information when exploited by authenticated users with low-level privileges (Malwarebytes, Jetpack Blog).

Mitigation and workarounds

Website owners are strongly advised to update to WP Fastest Cache version 0.9.5 or later, which contains the fix for this vulnerability. At the time of the initial disclosure, approximately 650,000 instances were still running vulnerable versions (Malwarebytes).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14478HIGH7.5
  • demo-importer-plus
NoYesJan 17, 2026
CVE-2025-8615MEDIUM6.4
  • cubewp-framework
NoYesJan 17, 2026
CVE-2025-14078MEDIUM5.3
  • woocommerce-for-paygent-payment-main
NoYesJan 17, 2026
CVE-2025-12129MEDIUM5.3
  • cubewp-framework
NoYesJan 17, 2026
CVE-2026-0725MEDIUM4.4
  • integrate-dynamics-365-crm
NoYesJan 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management