WP REST Cache
WP REST Cache has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 7.7, and the most serious one scores 8.1 out of 10. Severity breakdown: 0 critical and 2 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include PHP Remote File Inclusion.
Every one of the 2 issues recorded for WP REST Cache has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. WP REST Cache is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-52716WP REST Cache <= 2025.1.0 - Unauthenticated Local File Inclusion
Read the full analysisVulnerability Records

WP REST Cache
Author
Acato
Are you facing speed issues, using the WordPress REST API? This plugin will allow WordPress to cache the responses of the REST API, making it much faster. This plugin offers: Caching of all default WordPress REST API GET-endpoints. Caching of (custom) post type endpoints. Caching of (custom) taxonomy endpoints. Automated flushing of caches if (some of) its contents are edited. Manual flushing of all caches. Manual flushing of specific caches. A counter how many times a cache has been retrieved. Specifying after what time the cache should be timed out. Registering custom endpoints for caching. Automatic cache regeneration. WP REST Cache Pro For more advanced features, check out our WP REST Cache Pro plugin: Configure custom endpoints for caching through the wp-admin interface. Configure relationships within endpoints. No coding required. Installation from within WordPress Visit ‘Plugins > Add New’ (or ‘My Sites > Network Admin > Plugins > Add New’ if you are on a multisite installation). Search for ‘WP REST Cache’. Activate the WP REST Cache plugin through the ‘Plugins’ menu in WordPress. Go to “after activation” below. Installation manually Upload the wp-rest-cache folder to the /wp-content/plugins/ directory. Activate the WP REST Cache plugin through the ‘Plugins’ menu in WordPress. Go to “after activation” below. After activation Visit ‘Plugins > Must-Use’ (or ‘My Sites > Network Admin > Plugins > Must-Use’ if you are on a multisite installation). Check if the ‘WP REST Cache – Must-Use Plugin’ is there, if not copy the file wp-rest-cache.php from the /sources folder of the WP REST Cache Plugin to the folder /wp-content/mu-plugins/. Optionally: The default timeout for caches generated by the WP REST Cache plugin is set to 1 year. If you want to change this: Visit ‘Settings > WP REST Cache’. Change the Cache timeout.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C