Docket Cache – Object Cache Accelerator
Docket Cache – Object Cache Accelerator has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 7.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 1 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is PHP Remote File Inclusion, behind 2 of the records (50%). Other recurring categories include Cross-Site Scripting, Missing Authorization.
Every one of the 4 issues recorded for Docket Cache – Object Cache Accelerator has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, one record each. Docket Cache – Object Cache Accelerator is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-39461Docket Cache <= 24.07.02 - Unauthenticated Local File Inclusion
Read the full analysisVulnerability Records

Docket Cache – Object Cache Accelerator
Author
Nawawi Jamili
Docket Cache is a persistent WordPress Object Cache that stores cached data as plain PHP code. It is designed as an alternative for sites that do not have access to Redis or Memcached. Most file-based caching plugins use serializing and unserializing to save PHP objects to flat files. Docket Cache takes a different approach by converting objects into plain PHP code. This makes data retrieval faster and improves overall performance, especially when Zend OPcache is enabled. For more information, please refer to the documentation on Caching In WordPress. Why use this plugin? For reliable persistent Object Cache in WordPress, Redis or Memcached are the top choices. However, they require server knowledge and are rarely available on low-cost or shared hosting plans. The alternative is to store object caches in files. In WordPress, exporting PHP objects is not straightforward. Most file-based caching plugins rely on serialising and unserialising objects to store and retrieve data. Docket Cache takes a better approach by turning the object cache into plain PHP code. This is faster because WordPress can use the cache directly without additional processing. Features Object caching + OPcache Advanced Post Caching Object Cache Precaching WordPress Menu Caching WordPress Translation Caching WordPress Core Query Optimisation Term Count Queries Optimisation Post, Page, Comment Count Optimisation Database Tables Optimisation WooCommerce Optimisation WP Options Autoload suspension Post Missed Schedule Tweaks Object Cache + OPcache Stats + OPcache Viewer Cache Log Cronbot Service WP-CLI support Multisite / Multi-Network support Requirements To use Docket Cache requires minimum: PHP 7.2.5 WordPress 5.4 Zend OPcache Documentation For configuration options, installation guides, and command-line usage, please refer to the Documentation. Development GitHub Repository — Source code and development hub for Docket Cache. Changelog — Full history of changes, fixes, and improvements. Gapo Tunnel — Expose local services to the internet through secure tunnels. Useful for testing Docket Cache on a local development environment. WP Staging Desktop — Turn a live WordPress site into a local development environment in minutes. Sponsor This Project Support the ongoing development of Docket Cache with a one-off or recurring contribution. Noteworthy Sponsors: A heartfelt thanks and appreciation. Jimat Hosting Themecloud Websavers Inc Avunu LLC Linqru Gentleman’s Guru SecurePay DNSVault Exnano Creative Other sponsors are mentioned in the honourable list
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C