DIRAS TAKE
High priority — this can be triggered without authentication when Polylang and Combine JS are enabled; disable Combine JS or deactivate Polylang on public sites until the vendor issues a patch.
What is CVE-2026-19760?
Attackers can inject persistent JavaScript into cached pages served by the WP Fastest Cache WordPress plugin, causing that script to run in the browsers of later visitors. Tracked as CVE-2026-19760, this vulnerability affects WP Fastest Cache versions 1.5.0 and earlier. Exploitation depends on two conditions: the site has Polylang or Polylang Pro active, and the plugin’s Combine JS option is enabled; under those conditions an attacker can use crafted HTTP requests to manipulate cache output without any login. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of emrevona WP Fastest Cache – WordPress Cache Plugin are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.5.0 and earlier |
Is CVE-2026-19760 being exploited?
There are no public reports of exploitation or public exploit code as of 2026-09-29.
How to fix CVE-2026-19760
- Disable the Combine JS option in WP Fastest Cache immediately.
- Temporarily deactivate Polylang or Polylang Pro if possible.
- Harden exposure with a web application firewall rule blocking suspicious Host headers.
- Watch webserver and cache files for unexpected changes and review access logs for crafted requests.
- Install the vendor’s update as soon as a fixed release is published.
Frequently asked questions
Is CVE-2026-19760 being actively exploited?
There are no public reports of active exploitation of CVE-2026-19760 as of 2026-09-29.
Which WP Fastest Cache – WordPress Cache Plugin versions are affected by CVE-2026-19760?
WP Fastest Cache versions 1.5.0 and earlier are listed as affected.
Is there a patch for CVE-2026-19760?
No fixed version is listed in the available facts; apply vendor guidance and install a patch when the vendor releases one.
Does CVE-2026-19760 require authentication?
No, the issue can be exploited without authentication when Polylang is active and the Combine JS option is enabled.
References
- nvd.nist.gov/vuln/detail/CVE-2026-19760
- cve.org/CVERecord?id=CVE-2026-19760
- wordfence.com/threat-intel/vulnerabilities/id/69a22238-88e8-4ff5-8e2b-8c58a04ff154?source=cve
- plugins.trac.wordpress.org/browser/wp-fastest-cache/tags/1.5.0/inc/js-utilities.php#L274
- plugins.trac.wordpress.org/browser/wp-fastest-cache/tags/1.5.0/inc/js-utilities.php#L257
- plugins.trac.wordpress.org/browser/wp-fastest-cache/tags/1.5.0/wpFastestCache.php#L507
- plugins.trac.wordpress.org/browser/wp-fastest-cache/tags/1.4.9/inc/js-utilities.php#L274
- plugins.trac.wordpress.org/browser/wp-fastest-cache/tags/1.4.9/inc/js-utilities.php#L257
- plugins.trac.wordpress.org/browser/wp-fastest-cache/tags/1.4.9/wpFastestCache.php#L507
- All emrevona CVEs on CVE Radar
- CVEs published in September 2026