Varnish WordPress
Varnish WordPress has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Varnish WordPress has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by SOPROBRO. Varnish WordPress is installed on roughly 70 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.9.31.
CVE-2025-31616Varnish WordPress <= 1.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Varnish WordPress
Author
AdminGeekZ
This is a plugin for wordpress to intergrate the varnish cache for high performance websites. This plugin will purge the cache on, Post changes (new, edit, trash, delete). Page changes (add, edit, remove) Comment changes (add, edit, approve, unapprove, spam, trash, delete) Theme changes Features At present some of the features are, Multiple varnish backends Manually purge the cache Enable/Disable Feed Purging Ability to purge entire cache on changes Debug logging Minimize number of purges and remove duplicate purges for speed on larger installations Supports varnish 4 + 5 Support for Woocommerce Speed Our tests show that by utilizing varnish you gain a ~70x capacity increase over standard WordPress making you resistant to traffic floods (slashdot, digg, reddit, stumbleupon).
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C