Fastly <= 1.2.28 - Cross-Site Request Forgery
medium
The Fastly plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.28. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a s...
- CVSS:
- 4.3
- Affected:
- up to 1.2.28
- Fixed in:
- 1.2.29
- Disclosed:
- Sep 22, 2025
CVE-2025-58199 on NVD →
Fastly [fastly] < 1.2.26 (closed)
unknown
[en] Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.
- Affected:
- up to 1.2.26
- Fixed in:
- 1.2.26
- Disclosed:
- Jun 11, 2024
CVE-2024-34768 on NVD →
Fastly [fastly] < 1.2.26 (closed)
unknown
[en] Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.
- Affected:
- up to 1.2.26
- Fixed in:
- 1.2.26
- Disclosed:
- Jun 3, 2024
CVE-2024-34803 on NVD →
Fastly <= 1.2.25 - Missing Authorization
medium
The Fastly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in versions up to, and including, 1.2.25. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several unauthorized actions like tes...
- CVSS:
- 4.3
- Affected:
- up to 1.2.25
- Fixed in:
- 1.2.26
- Disclosed:
- May 20, 2024
CVE-2024-34803 on NVD →
Fastly <= 1.2.25 - Missing Authorization via AJAX actions
medium
The Fastly plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the plugin's AJAX actions in versions up to, and including, 1.2.25. This makes it possible for authenticated attackers, with subscriber-level access and above, to invoke functions intended for admi...
- CVSS:
- 4.3
- Affected:
- up to 1.2.25
- Fixed in:
- 1.2.26
- Disclosed:
- May 17, 2024
CVE-2024-34768 on NVD →
Fastly [fastly] < 0.98 (closed)
unknown
[en] A vulnerability was found in Fastly Plugin up to 0.97 on WordPress. It has been rated as problematic. Affected by this issue is the function post of the file lib/api.php. The manipulation of the argument url leads to cross site scripting. The attack may be launched remotely. Upgrading to version 0.98 is able to ad...
- Affected:
- up to 0.98
- Fixed in:
- 0.98
- Disclosed:
- Mar 6, 2023
CVE-2015-10094 on NVD →
Fastly <= 0.97 - Reflected Cross-Site Scripting
medium
The Fastly plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 0.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 0.97
- Fixed in:
- 0.98
- Disclosed:
- Feb 3, 2015
CVE-2015-10094 on NVD →
Fastly [fastly] <= 1.2.28 (unfixed)
unknown
- Affected:
- up to 1.2.28
- Fix:
- No patched version reported
CVE-2025-58199 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database