CVE-2026-19760: pre-auth stored cross-site scripting in emrevona WP Fastest Cache – WordPress Cache Plugin

Attackers can inject persistent JavaScript into cached pages served by the WP Fastest Cache WordPress plugin, causing that script to run in the browsers of later visitors. Tracked as CVE-2026-19760, this vulnerability affects WP Fastest Cache versions 1.5.0 and earlier. Exploitation depends on two conditions: the site has Polylang or Polylang Pro active, and the plugin’s Combine JS option is enabled; under those conditions an attacker can use crafted HTTP requests to manipulate cache output without any login.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.2HIGH
EPSS
0.00404
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

High priority — this can be triggered without authentication when Polylang and Combine JS are enabled; disable Combine JS or deactivate Polylang on public sites until the vendor issues a patch.

What is CVE-2026-19760?

Attackers can inject persistent JavaScript into cached pages served by the WP Fastest Cache WordPress plugin, causing that script to run in the browsers of later visitors. Tracked as CVE-2026-19760, this vulnerability affects WP Fastest Cache versions 1.5.0 and earlier. Exploitation depends on two conditions: the site has Polylang or Polylang Pro active, and the plugin’s Combine JS option is enabled; under those conditions an attacker can use crafted HTTP requests to manipulate cache output without any login. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Which versions of emrevona WP Fastest Cache – WordPress Cache Plugin are affected?

BRANCHAFFECTEDFIXED
1.x1.5.0 and earlier

Is CVE-2026-19760 being exploited?

There are no public reports of exploitation or public exploit code as of 2026-09-29.

How to fix CVE-2026-19760

  1. Disable the Combine JS option in WP Fastest Cache immediately.
  2. Temporarily deactivate Polylang or Polylang Pro if possible.
  3. Harden exposure with a web application firewall rule blocking suspicious Host headers.
  4. Watch webserver and cache files for unexpected changes and review access logs for crafted requests.
  5. Install the vendor’s update as soon as a fixed release is published.

Frequently asked questions

Is CVE-2026-19760 being actively exploited?

There are no public reports of active exploitation of CVE-2026-19760 as of 2026-09-29.

Which WP Fastest Cache – WordPress Cache Plugin versions are affected by CVE-2026-19760?

WP Fastest Cache versions 1.5.0 and earlier are listed as affected.

Is there a patch for CVE-2026-19760?

No fixed version is listed in the available facts; apply vendor guidance and install a patch when the vendor releases one.

Does CVE-2026-19760 require authentication?

No, the issue can be exploited without authentication when Polylang is active and the Combine JS option is enabled.

References