Varnish/Nginx Proxy Caching
Varnish/Nginx Proxy Caching has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; none of them are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor.
None of the 2 issues recorded for Varnish/Nginx Proxy Caching have a published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
2 independent researchers contributed these findings, one record each. Varnish/Nginx Proxy Caching is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.2.26.
CVE-2025-62126Varnish/Nginx Proxy Caching <= 1.8.3 - Unauthenticated Information Exposure
Read the full analysisVulnerability Records

Varnish/Nginx Proxy Caching
Author
Razvan Stanga
Complete WordPress Varnish Cache 3.x/4.x/5.x and Nginx Proxy Cache integration. This plugin handles all integration with Varnish Cache and Nginx Proxy Cache. It was designed for high traffic websites. Main features admin interface, see screenshots console for manual purges, supports regular expressions so you can purge an entire folder or just a single file supports every type of Varnish Cache implementation, see screenshots for examples unlimited number of Varnish Cache servers use of custom headers when communicating with Varnish Cache does not interfere with other caching plugins, cloudflare, etc Varnish Cache configuration generator purge key method so you don’t need to setup ACLs debugging actively maintained You can control the following from the Varnish Caching admin panel : Enable/Disable caching Homepage cache TTL Cache TTL (for every other page) IPs/Hosts to clear cache to support every type of Varnish Cache implementation Override default TTL in posts/pages Purge key based PURGE Logged in cookie Debugging option console for precise manual purges This plugin also auto purges Varnish Cache / Nginx Proxy Cache when your site is modified. Varnish Caching sends a PURGE request to Varnish Cache / Nginx Proxy Cache when a page or post is modified. This occurs when editing, publishing, commenting or deleting an item, and when changing themes. Not all pages are purged every time, depending on your Varnish / Nginx Proxy Cache configuration. When a post, page, or custom post type is edited, or a new comment is added, only the following pages will purge: The front page The post/page edited Any categories or tags associated with the page Varnish Cache / Nginx Proxy Cache is a web application accelerator also known as a caching HTTP reverse proxy. You install it in front of any server that speaks HTTP and configure it to cache the contents. This plugin does not install Varnish/Nginx for you, nor does it configure Varnish/Nginx for WordPress. It’s expected you already did that on your own using the provided config files. Inspired from the following : https://wordpress.org/plugins/varnish-http-purge/ https://github.com/dreamhost/varnish-vcl-collection/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C