{"error":0,"message":null,"data":{"name":"W3 Total Cache","plugin":"w3-total-cache","link":"https:\/\/wordpress.org\/plugins\/w3-total-cache\/","latest":"1788541200","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"2d856370984ade5cfa4930274543d6d2a39a3d454605032687a68f8a9a63053a","name":"W3 Total Cache [w3-total-cache] < 2.1.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24452","name":"CVE-2021-24452","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24452","description":"[en] The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the \"extension\" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper escaping. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.","date":"2021-07-19"},{"id":"1472d659055759fe63113015a67295e04481f5f2","name":"WordPress W3 Total Cache plugin <= 2.1.4 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-2-1-4-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by renniepak in WordPress W3 Total Cache plugin (versions <= 2.1.4).","date":"2021-06-28"},{"id":"3e855e09-056f-45b5-89a9-d644b7d8c9d0","name":"W3 Total Cache &lt; 2.1.5 - Reflected XSS in Extensions Page (JS Context)","link":"https:\/\/wpscan.com\/vulnerability\/3e855e09-056f-45b5-89a9-d644b7d8c9d0","description":"The plugin was affected by a reflected Cross-Site Scripting (XSS) issue within the &quot;extension&quot; parameter in the Extensions dashboard, when the &#039;Anonymously track usage to improve product quality&#039; setting is enabled, as the parameter is output in a JavaScript context without proper escaping. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user&#039;s web browser, which could lead to full site compromise.","date":null},{"id":"309994dad88cd12201ff35e0a6d4591defd260ee","name":"W3 Total Cache <= 2.1.4 - Reflected Cross-Site Scripting via extension","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-214-reflected-cross-site-scripting-via-extension","description":"The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the \"extension\" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper escaping. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.","date":"2021-06-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"231216c2172c795844b01fbf04fcf8329305e8bb22ac99eb4e9ceb5ca22a1b5c","name":"W3 Total Cache [w3-total-cache] < 2.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24436","name":"CVE-2021-24436","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24436","description":"[en] The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the \"extension\" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.","date":"2021-07-19"},{"id":"15b5ec1abea733b0f36a4a2bf77014bf97107861","name":"WordPress W3 Total Cache plugin <= 2.1.3 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-2-1-3-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by renniepak in WordPress W3 Total Cache plugin (versions <= 2.1.3).","date":"2021-06-28"},{"id":"05988ebb-7378-4a3a-9d2d-30f8f58fe9ef","name":"W3 Total Cache &lt; 2.1.4 - Reflected XSS in Extensions Page (Attribute Context)","link":"https:\/\/wpscan.com\/vulnerability\/05988ebb-7378-4a3a-9d2d-30f8f58fe9ef","description":"The plugin was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the &quot;extension&quot; parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user&#039;s web browser, which could lead to full site compromise.","date":null},{"id":"c3a3739b0986c798a2cade633fe2321566840f86","name":"W3 Total Cache <= 2.1.3 - Reflected Cross-Site Scripting via extension","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-213-reflected-cross-site-scripting-via-extension","description":"The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the \"extension\" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.","date":"2021-06-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"42e7de6efcddc2a7fdc302699ebeaf458280694172cf49589045e903bea0f970","name":"W3 Total Cache [w3-total-cache] < 2.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24427","name":"CVE-2021-24427","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24427","description":"[en] The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue","date":"2021-07-12"},{"id":"65ab949cb70cdcac4207905731a90eecc70c5aa4","name":"WordPress W3 Total Cache plugin <= 2.1.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-2-1-2-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress W3 Total Cache plugin (versions <= 2.1.2).","date":"2021-04-25"},{"id":"5da5ce9a-82a6-404f-8dec-795d7905b3f9","name":"W3 Total Cache &lt; 2.1.3 - Authenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/5da5ce9a-82a6-404f-8dec-795d7905b3f9","description":"The plugin did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue","date":null},{"id":"f5235b1349532312c6d216aa669498477da76b4a","name":"W3 Total Cache <= 2.1.2 Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-212-authenticated-admin-stored-cross-site-scripting","description":"The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several CDN settings in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2021-06-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"09e3d9abf4ce3fe467de4c3cb1f8d025f0b29d3058d2cdeb203d147a1bb420b0","name":"W3 Total Cache [w3-total-cache] < 0.9.2.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.2.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2013-2010","name":"CVE-2013-2010","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2013-2010","description":"[en] WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability","date":"2020-02-12"},{"id":"96254d53-ae58-443d-8acc-b67a05d2ad75","name":"W3 Total Cache - Remote Code Execution","link":"https:\/\/wpscan.com\/vulnerability\/96254d53-ae58-443d-8acc-b67a05d2ad75","description":"The W3 Total Cache WordPress plugin was affected by a Remote Code Execution security vulnerability.","date":null},{"id":"1bdab6a65aafbab1669d00d65526f507d16df981","name":"W3 Total Cache <= 0.9.2.8 - Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-0928-remote-code-execution","description":"WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability","date":"2014-08-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-74","name":"Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","description":"The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component."}]}},{"uuid":"35d71384aac4c13c7d907d36da734bb9876b0c5be8c997cb246be156b5731e41","name":"W3 Total Cache [w3-total-cache] < 0.9.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-6715","name":"CVE-2019-6715","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-6715","description":"[en] pub\/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.","date":"2019-04-01"},{"id":"692eac9d-2b17-4b18-94fe-b0d353bdacd6","name":"W3 Total Cache 0.9.2.6-0.9.3 - Unauthenticated Arbitrary File Read","link":"https:\/\/wpscan.com\/vulnerability\/692eac9d-2b17-4b18-94fe-b0d353bdacd6","description":"The W3 Total Cache WordPress plugin was affected by an Unauthenticated Arbitrary File Read security vulnerability.","date":null},{"id":"00a56e0b49ff74b482537b287052d999eedca607","name":"W3 Total Cache 0.9.2.6-0.9.3 - File Read \/ Directory Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-0926-093-file-read-directory-traversal","description":"The script pub\/sns.php in the W3 Total Cache plugin (versions 0.9.2.6 through 0.9.3) allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.","date":"2020-12-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"}}},{"uuid":"278ad12d8cccbe86534ba76e35328153b2a981283d56a09196213c76906c4bcc","name":"W3 Total Cache [w3-total-cache] < 0.9.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-9414","name":"CVE-2014-9414","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-9414","description":"[en] The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parameter and an empty _wpnonce parameter in the w3tc_mobile page to wp-admin\/admin.php.","date":"2014-12-24"},{"id":"e0cd78c88b165ed039c89d3677b84b6a412868e0","name":"WordPress W3 Total Cache plugin <= 0.9.4 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-csrf","description":"WordPress W3 Total Cache plugin's \"admin.php\" is prone to a cross-site request forgery vulnerability. It allows an attacker to gain unauthorized access to the affected application by performing certain actions in the context of an authorized user's session.\nUpdate the WordPress W3 Total Cache plugin to the latest available version (at least 0.9.5)","date":"2014-09-08"},{"id":"d460073f-cfc4-4ac7-b008-5462e6f0b7bf","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/d460073f-cfc4-4ac7-b008-5462e6f0b7bf","description":null,"date":null},{"id":"a1923d46e200dd50daf4e394a9a85d4ad508ab6f","name":"W3 Total Cache <= 0.9.4 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-094-cross-site-request-forgery","description":"The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parameter and an empty _wpnonce parameter in the w3tc_mobile page to wp-admin\/admin.php.","date":"2014-12-10"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"8a29790354d4bc5bc64bdb432b98b19586bbd5336be52a25ecf326bd3f2e4729","name":"W3 Total Cache [w3-total-cache] < 0.9.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-8724","name":"CVE-2014-8724","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-8724","description":"[en] Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the \"Cache key\" in the HTML-Comments, as demonstrated by the PATH_INFO to the default URI.","date":"2014-12-19"},{"id":"8f2664cffa2269f50bd6747f03974f6f67c22e36","name":"WordPress W3 Total Cache Plugin <= 0.9.4 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-0-9-4-xss","description":"Because of this vulnerability, the  attackers can inject arbitrary web script or HTML via the \"Cache key\" in the HTML-Comments.\nUpdate the plugin.","date":"2014-11-10"},{"id":"3eea73af-e0a1-493c-a268-0cf340cb39a4","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/3eea73af-e0a1-493c-a268-0cf340cb39a4","description":null,"date":null},{"id":"0f7f2f8c6a238f9b27bc49c0479c03a220716324","name":"W3 Total Cache <= 0.9.4 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-094-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the \"Cache key\" in the HTML-Comments, as demonstrated by the PATH_INFO to the default URI.","date":"2014-12-16"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"3babf47eb5364642e970bee109a3b8849ba44c8fb81eb03c07ca8cfdda52a99d","name":"W3 Total Cache [w3-total-cache] < 0.9.7.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.7.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0922cc61c0a7483985f79748dccdee296b0f6729","name":"WordPress W3 Total Cache plugin <= 0.9.7.3 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-0-9-7-3-cross-site-scripting-xss-vulnerability","description":"Cross-Site Scripting (XSS) vulnerability found by Thomas Chauchefoin in WordPress W3 Total Cache plugin (versions <= 0.9.7.3).","date":"2019-05-07"}],"impact":[]},{"uuid":"4cd16c8377a324432b952cc9d315063b8e6315421a146c95d677f2778dabb2eb","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0fe7a6f62fbcb8ec10bdee902c9620cfce4af778","name":"WordPress W3 Total Cache Plugin <= 0.9.4.1 - Bypass","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-0-9-4-1-bypass","description":"This plugin is prone to unauthenticated security token bypass vulnerability.\nUpdate the plugin.","date":"2016-09-27"}],"impact":[]},{"uuid":"d05a451389f7e9dbe7af25fc627942c0b891bb95a2acdcddb84666102ae9cc3e","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"887fbfcb2894d958d0915dea688fc101acf4d15a","name":"WordPress W3 Total Cache Plugin <= 0.9.4.1 - Arbitrary File Upload","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-0-9-4-1-arbitrary-file-upload","description":"This plugin is prone to an authenticated arbitrary file upload vulnerability.\nUpdate the plugin.","date":"2016-09-27"}],"impact":[]},{"uuid":"bf344bf3a262cf47ac5f46581c6f311e5f749c5e5ec86fbf85b5d98f1e940777","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3d94635fdc144f68425abe52237de17b1b89efcc","name":"WordPress W3 Total Cache Plugin <= 0.9.4.1 - Arbitrary File Download","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-0-9-4-1-arbitrary-file-download","description":"This plugin is prone to  authenticated arbitrary file download vulnerability.\nUpdate the plugin.","date":"2016-09-27"}],"impact":[]},{"uuid":"c088b8f02483d603bdd763dcc4ba25f5bbd9aacc1a76f19b80c0236139d68092","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"91816c620bff939df0db1b9923ab56362614d8ff","name":"WordPress W3 Total Cache Plugin <= 0.9.4.1 - Arbitrary PHP Code Execution","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-0-9-4-1-arbitrary-php-code-execution","description":"This plugin is prone to an authenticated arbitrary PHP code execution vulnerability.\nUpdate the plugin.","date":"2016-09-27"}],"impact":[]},{"uuid":"2ee9c58fe403aa38de67d46b1bd0816385250983bb85a7f385f0dc8a0a4a548a","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6997ee28e3d8ea8b4131bc872c0aa1712376622f","name":"WordPress W3 Total Cache Plugin <= 0.9.4.1 - Reflected Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-0-9-4-1-reflected-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2016-09-26"}],"impact":[]},{"uuid":"fc8e1afbc29b2b2f5c82c847e902defa4fc28dbcd08d0a901c6b23bce13ee563","name":"W3 Total Cache [w3-total-cache] < 0.9.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f3337db796050925ade10a6a14847e57c053e3ab","name":"WordPress W3 Total Cache Plugin <= 0.9.4 - Cross Site Request Forgery","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-0-9-4-cross-site-request-forgery","description":"This plugin is prone to edge mode enabling cross site request forgery vulnerability.\nUpdate the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"b7d84268101e69a510a5695ded2b0f35254ee62ad8244860c583cfd4be0b63a5","name":"W3 Total Cache [w3-total-cache] < 0.9.2.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.2.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f4dd379d6047628a42a4e08403e5ed8d741577c7","name":"WordPress W3 Total Cache plugin <= 0.9.2.8 - PHP Code Execution vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-php-code-execution","description":"W3 Total Cache plugin is prone to a PHP code execution vulnerability because of the handling of certain macros such as \"mfunc\" that allows arbitrary PHP code injection.\nUpdate the WordPress W3 Total Cache plugin to the latest available version (at least 0.9.2.9).","date":"2013-05-01"}],"impact":[]},{"uuid":"c9ae90c085c5ed74cfa954ce492f2d6dc3e573098a9d89974f06ecd1d8e162ed","name":"W3 Total Cache [w3-total-cache] < 0.9.7.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.7.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f8409eab-b434-468d-9a0a-66e8bb85d4fc","name":"W3 Total Cache &lt; 0.9.7.3 - Cryptographic Signature Bypass","link":"https:\/\/wpscan.com\/vulnerability\/f8409eab-b434-468d-9a0a-66e8bb85d4fc","description":"The return value of `openssl_verify` is not properly validated, which allows to bypass the cryptographic check.","date":null}],"impact":[]},{"uuid":"be36adef83e7795839167797ad4f62c5fb5e42e49247c0bddaa750e777e05549","name":"W3 Total Cache [w3-total-cache] < 0.9.7.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.7.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0f23fa7c-ddeb-4dfb-9718-2cbff24cffe7","name":"W3 Total Cache &lt; 0.9.7.4 - Blind SSRF and RCE via phar","link":"https:\/\/wpscan.com\/vulnerability\/0f23fa7c-ddeb-4dfb-9718-2cbff24cffe7","description":"The implementation of `opcache_flush_file` calls `file_exists` with a parameter fully controlled by the user.","date":null}],"impact":[]},{"uuid":"7da01952c212fea82421e2e1a655b897ac173b268612ed248a2ea862e64ff136","name":"W3 Total Cache [w3-total-cache] < 0.9.7.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.7.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6dbb1a21-9805-401b-8cd4-f7c387c99199","name":"W3 Total Cache &lt;= 0.9.7.3 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/6dbb1a21-9805-401b-8cd4-f7c387c99199","description":"The W3 Total Cache WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"cd739fbff58217d3b9e365fae39eb4a3d49a31bdffa5c701c7fc7a591a2c8f06","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"70c644e0-3d60-4f97-bdbb-39b5cec25c7f","name":"W3 Total Cache &lt;= 0.9.4.1 - Weak Validation of Amazon SNS Push Messages","link":"https:\/\/wpscan.com\/vulnerability\/70c644e0-3d60-4f97-bdbb-39b5cec25c7f","description":"The W3 Total Cache WordPress plugin was affected by a Weak Validation of Amazon SNS Push Messages security vulnerability.","date":null}],"impact":[]},{"uuid":"ab53cd5cc90f15cb9d8111eeef002f393fafd299bd72c439b6ae44951b87d2d2","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e9f01529-7f46-4044-aee2-bdda910cb6ac","name":"W3 Total Cache &lt;= 0.9.4.1 - Information Disclosure Race Condition","link":"https:\/\/wpscan.com\/vulnerability\/e9f01529-7f46-4044-aee2-bdda910cb6ac","description":"The W3 Total Cache WordPress plugin was affected by an Information Disclosure Race Condition security vulnerability.","date":null}],"impact":[]},{"uuid":"dbf674a85dc2bd6ad4f80524c09b5c4b4a6ecaf028c3de0d1b1f585414fa69bd","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8835ac84-9176-44f6-9218-7022debf0eab","name":"W3 Total Cache &lt;= 0.9.4 - Unauthenticated Server Side Request Forgery (SSRF)","link":"https:\/\/wpscan.com\/vulnerability\/8835ac84-9176-44f6-9218-7022debf0eab","description":"The W3 Total Cache WordPress plugin was affected by an Unauthenticated Server Side Request Forgery (SSRF) security vulnerability.","date":null}],"impact":[]},{"uuid":"496a80c3fbe6887171134607ec66bf44d9c19b6aafc91f945fe894521137b9a3","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"cbcbc279-3feb-4bb5-a53d-287961bbc18f","name":"W3 Total Cache &lt;= 0.9.4.1 &ndash; Authenticated Arbitrary File Download","link":"https:\/\/wpscan.com\/vulnerability\/cbcbc279-3feb-4bb5-a53d-287961bbc18f","description":"When you&#039;re creating a support ticket in the plugin page, you can add one or more of your your template themes.\r\n\r\nThen this file will be send to the author to help him resolving the issue.\r\n\r\nNow you select one, you send the form and same as for the files before, you will send it to the author to help him to fix the issue.\r\n\r\nHow does it work:\r\n**********\r\n        \/**\r\n         * Attach templates\r\n         *\/\r\n        foreach ($templates as $template) {\r\n            if (!empty($template)) {\r\n                $attachments[] = $template;\r\n            }\r\n        }\r\n**********\r\n        foreach ($attachments as $attachment) {\r\n            if (is_network_admin())\r\n                update_site_option(&#039;attachment_&#039; . md5($attachment), $attachment);\r\n            else\r\n                update_option(&#039;attachment_&#039; . md5($attachment), $attachment);\r\n        }\r\n**********\r\n        \/**\r\n         * Remove temporary files\r\n         *\/\r\n        foreach ($attachments as $attachment) {\r\n\/\/ ...\r\n            if (is_network_admin())\r\n                delete_site_option(&#039;attachment_&#039; . md5($attachment));\r\n            else\r\n                delete_option(&#039;attachment_&#039; . md5($attachment));\r\n        }\r\n**********\r\n$attachment_location = filter_var(urldecode($_REQUEST[&#039;file&#039;]), FILTER_SANITIZE_STRING);\r\n$md5 = md5($attachment_location);\r\n$nonce = $_REQUEST[&#039;nonce&#039;];\r\n$stored_nonce = get_site_option(&#039;w3tc_support_request&#039;) ? get_site_option(&#039;w3tc_support_request&#039;) : get_option(&#039;w3tc_support_request&#039;);\r\n$stored_attachment = get_site_option(&#039;w3tc_support_request&#039;) ? get_site_option(&#039;attachment_&#039; . $md5) : get_option(&#039;attachment_&#039; . $md5);\r\n\r\nif (file_exists($attachment_location) &amp;&amp; $nonce == $stored_nonce &amp;&amp; !empty($stored_nonce) &amp;&amp; $stored_attachment == $attachment_location) {\r\n**********\r\n\r\nFirst, our choices are added to the attachments array, second an option is added, this will be used to be sure that this file was chosen from this support form, then this options are deleted when the submission is done.\r\n\r\nBetween the option creation and delete that the files.php is called to get the attachment, verified with a nonce and with the created option.\r\n\r\nThe vulnerability stays in the fact that we can modify &ndash; using firebug for example &ndash; the templates name to another existing file from the site, like wp-config.php.\r\n\r\nSo now, an option has been created with this fake theme template. Then using the same type juggling flaw as before, I can validate the nonce because of the ==.\r\n\r\nYou also have to add a 20 Mb file to gain time to exploit this.\r\n\r\nPointing on the files.php URL like that can help me to download the wp-config.php, because for the same reason as before, an administrator is not always allowed to read the config file, he&#039;s not the webmaster but a WordPress administrator, so this represent a vulnerability.","date":null}],"impact":[]},{"uuid":"c73529fa08d58687957676b94867d484af1cc2d09206be2f811d3698fd293df4","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"666d4a0d-f925-4582-b621-1c913dffb894","name":"W3 Total Cache &lt;= 0.9.4.1 &ndash; Authenticated Arbitrary File Upload","link":"https:\/\/wpscan.com\/vulnerability\/666d4a0d-f925-4582-b621-1c913dffb894","description":"When you&#039;re creating a support ticket in the plugin page, you can add one or more of your files from your computer.\r\n\r\nThen this file will be send to the author to help him resolving the issue.\r\n\r\nWhen we look at the code, W3TC is doing that:\r\n**********\r\n        \/**\r\n         * Attach other files\r\n         *\/\r\n        if (!empty($_FILES[&#039;files&#039;])) {\r\n            $files = (array)$_FILES[&#039;files&#039;];\r\n            for ($i = 0, $l = count($files); $i &lt; $l; $i++) {\r\n                if (isset($files[&#039;tmp_name&#039;][$i]) &amp;&amp; isset($files[&#039;name&#039;][$i]) &amp;&amp; isset($files[&#039;error&#039;][$i]) &amp;&amp; $files[&#039;error&#039;][$i] == UPLOAD_ERR_OK) {\r\n                    $path = W3TC_CACHE_TMP_DIR . &#039;\/&#039; . $files[&#039;name&#039;][$i];\r\n                    if (@move_uploaded_file($files[&#039;tmp_name&#039;][$i], $path)) {\r\n                        $attachments[] = $path;\r\n                    }\r\n                }\r\n            }\r\n        }\r\n**********\r\nand\r\n**********\r\n        \/**\r\n         * Remove temporary files\r\n         *\/\r\n        foreach ($attachments as $attachment) {\r\n            if (strstr($attachment, W3TC_CACHE_TMP_DIR) !== false) {\r\n                @unlink($attachment);\r\n            }\r\n**********\r\n\r\nOk, so, when you submit the form as an administrator, W3TC uploads our file in its temporary folder \/wp-content\/cache\/tmp\/ then will delete them right after that, the file will live only a few milliseconds.\r\n\r\nBut what if I try to send 2 files, the first one is a 2 Kb malicious PHP file containing a backdoor, the second one is a 20 Mb file. The submission will last more longer, the first file won&#039;t be deleted since the second one is not uploaded, I can now access to the first file.\r\n\r\nAn administrator is not always allowed to execute custom PHP code, he&#039;s not the webmaster but a WordPress administrator, so this represent a vulnerability.","date":null}],"impact":[]},{"uuid":"0d687c278bed1733870d91d5a26779aa854e06a418b6c0733cb584551c50f2b8","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"752fc738-496f-44fd-9ca6-24e29ef8e75e","name":"W3 Total Cache &lt;= 0.9.4.1 &ndash; Authenticated Arbitrary PHP Code Execution","link":"https:\/\/wpscan.com\/vulnerability\/752fc738-496f-44fd-9ca6-24e29ef8e75e","description":"This one is so mush easy to exploit using the import settings feature, this is what W3TC will do one your file is uploaded:\r\n**********\r\n    \/**\r\n     * Imports config content\r\n     *\r\n     * @param string $filename\r\n     * @return boolean\r\n     *\/\r\n    function import($filename) {\r\n        if (file_exists($filename) &amp;&amp; is_readable($filename)) {\r\n            $data = file_get_contents($filename);\r\n            if (substr($data, 0, 5) == &#039;&lt;?php&#039;)\r\n                $data = substr($data, 5);\r\n\r\n            $config = eval($data);\r\n\r\n            if (is_array($config)) {\r\n                foreach ($config as $key =&gt; $value)\r\n                  $this-&gt;set($key, $value);\r\n\r\n                return true;\r\n            }\r\n        }\r\n\r\n        return false;\r\n    }\r\n**********\r\nThe bad line is $config = eval($data); because it means that all my file content will be evaluated like any other PHP code. Basically we can send a PHP script that will create a backdoor.","date":null}],"impact":[]},{"uuid":"3b859375772fa93b4f2e98f4462955c53c8299f4ecaf30af2cefa984155e37e4","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3b66bd46-b266-4f3b-ae74-823586e73ebd","name":"W3 Total Cache &lt;= 0.9.4.1 &ndash; Unauthenticated Security Token Bypass","link":"https:\/\/wpscan.com\/vulnerability\/3b66bd46-b266-4f3b-ae74-823586e73ebd","description":"The \/pub\/apc.php file is used to empty the OPCache\/APC. The script seems protected by a nonce (aka security token):\r\n***********\r\n$nonce = W3_Request::get_string(&#039;nonce&#039;);\r\n$uri = $_SERVER[&#039;REQUEST_URI&#039;];\r\n\r\nif (wp_hash($uri) == $nonce) {\r\n************\r\n\r\nBut the flaw stays in the == operator which is not the one to use when you want to compare hashes because of php type juggling.\r\n\r\nYou can find an example of type juggling on https:\/\/3v4l.org\/tT4l8\r\n\r\nTo exploit the vulnerability, the token has to start with `0e` and all other chars have to be numbers, then the user can just add a param in the url like `?nonce=0` and it will be validated.","date":null}],"impact":[]},{"uuid":"672d8e5c408724c6b1b41ac31004fcc4f3b355db5116657b645fc6dbd13d99fc","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ab678c61-7609-4497-82b4-3cbbc84081a2","name":"W3 Total Cache &lt;= 0.9.4.1 - Authenticated Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/ab678c61-7609-4497-82b4-3cbbc84081a2","description":"The W3 Total Cache WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"d955509b0e33b9a931dd8c768cb22908446476cdfb91223772c1fd4e9e7bf07f","name":"W3 Total Cache [w3-total-cache] < 0.9.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b6817692-4f97-4f8c-907c-7e7c8492d43a","name":"W3 Total Cache 0.9.4 - Edge Mode Enabling CSRF","link":"https:\/\/wpscan.com\/vulnerability\/b6817692-4f97-4f8c-907c-7e7c8492d43a","description":"The W3 Total Cache WordPress plugin was affected by an Edge Mode Enabling CSRF security vulnerability.","date":null}],"impact":[]},{"uuid":"eceb02e03842b3474292b1ca846c23977ae61061e5fd5f0dd10d78a03f739f46","name":"W3 Total Cache [w3-total-cache] < 0.9.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2012-6078","name":"CVE-2012-6078","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2012-6078","description":"[en] W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.","date":"2019-11-22"},{"id":"b71d8f6e-4d35-482e-a8a1-e45b9e1bfbdc","name":"W3 Total Cache 0.9.2.4 - Username &amp; Hash Extract","link":"https:\/\/wpscan.com\/vulnerability\/b71d8f6e-4d35-482e-a8a1-e45b9e1bfbdc","description":"The W3 Total Cache WordPress plugin was affected by an Username &amp; Hash Extract security vulnerability.","date":null},{"id":"9c1290808ce966b1ab54bf84594e7aa8155f03ad","name":"W3 Total Cache <= 0.9.2.4 - Insecure Cryptography to Sensitive Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-0924-insecure-cryptography-to-sensitive-information-disclosure","description":"W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.","date":"2020-09-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}]}},{"uuid":"338f1e6cbaf02258ce0fb8d6c871fef9a389df205f7a497c0d11cc7cc6976f63","name":"W3 Total Cache [w3-total-cache] < 2.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-31090","name":"CVE-2022-31090","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-31090","description":"[en] Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` header. On making a request which responds with a redirect to a URI with a different origin (change in host, scheme or port), if we choose to follow it, we should remove the `CURLOPT_HTTPAUTH` option before continuing, stopping curl from appending the `Authorization` header to the new request. Affected Guzzle 7 users should upgrade to Guzzle 7.4.5 as soon as possible. Affected users using any earlier series of Guzzle should upgrade to Guzzle 6.5.8 or 7.4.5. Note that a partial fix was implemented in Guzzle 7.4.2, where a change in host would trigger removal of the curl-added Authorization header, however this earlier fix did not cover change in scheme or change in port. If you do not require or expect redirects to be followed, one should simply disable redirects all together. Alternatively, one can specify to use the Guzzle steam handler backend, rather than curl.","date":"2022-06-27"},{"id":"1dc6be58e2ea398c6de65afa53ffd4532b0bc449","name":"Guzzle <= 6.5.7 and 7.0-7.4.4 - Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/guzzle-657-and-70-744-information-exposure","description":"Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` header. On making a request which responds with a redirect to a URI with a different origin (change in host, scheme or port), if we choose to follow it, we should remove the `CURLOPT_HTTPAUTH` option before continuing, stopping curl from appending the `Authorization` header to the new request. Affected Guzzle 7 users should upgrade to Guzzle 7.4.5 as soon as possible. Affected users using any earlier series of Guzzle should upgrade to Guzzle 6.5.8 or 7.4.5. Note that a partial fix was implemented in Guzzle 7.4.2, where a change in host would trigger removal of the curl-added Authorization header, however this earlier fix did not cover change in scheme or change in port. If you do not require or expect redirects to be followed, one should simply disable redirects all together. Alternatively, one can specify to use the Guzzle steam handler backend, rather than curl. *Please note that while some WordPress plugins and themes may use this as a dependency, they may not be directly exploitable.","date":"2022-06-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"h","i":"n","a":"n","score":"7.7","severity":"h","exploitable":"3.1","impact":"4.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:N\/A:N","score":"7.7","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"high","i":"none","a":"none","exploitable":"3.1","impact":"4.0"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."},{"cwe":"CWE-212","name":"Improper Removal of Sensitive Information Before Storage or Transfer","description":"The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b3b7a4a3d443db736acc0dee0af6ebb3609f110ea1d8fee4c26a03ae7881e2a5","name":"W3 Total Cache [w3-total-cache] < 0.9.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2012-6077","name":"CVE-2012-6077","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2012-6077","description":"[en] W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.","date":"2019-11-22"},{"id":"ff2190cabc9ad7beec1e9c9544c4f8e2a30f1f9c","name":"W3 Total Cache <= 0.9.2.4 - Password Hash Extraction","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-0924-password-hash-extraction","description":"W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.","date":"2020-09-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}]}},{"uuid":"6f770e5394104168f5f7e00ebe2020c029d2a39e12b2ad191779d6ead2531e23","name":"W3 Total Cache [w3-total-cache] < 0.9.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2012-6079","name":"CVE-2012-6079","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2012-6079","description":"[en] W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.","date":"2019-11-22"},{"id":"0678390382a79a9fcd5ebe83fa2133f2ae3b8e4f","name":"W3 Total Cache <= 0.9.2.4 - Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-0924-sensitive-information-exposure","description":"W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.","date":"2020-09-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}]}},{"uuid":"2cc0f858820e1d64e0a04ac056f12e84c6b5ddfa560131ce0aab1d2c47c4a793","name":"W3 Total Cache [w3-total-cache] < 0.9.7.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.7.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8914eae9e90e5064c78effaf3b28a4eed5695eb0","name":"W3 Total Cache <= 0.9.7.3 - Server Side Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-0973-server-side-request-forgery","description":"The W3 Total Cache plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including 0.9.7.3, due to insufficient user input validation in the opcache_flush_file file.","date":"2019-05-22"}],"impact":[]},{"uuid":"6e0c6fcf8e01fe63efd2e9a5be438a3dd42a554d8832a0254edb0f0f44f79584","name":"W3 Total Cache [w3-total-cache] < 0.9.7.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.7.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7f3b8aa7e2f030804e7f93da0c1085499f696a4b","name":"W3 Total Cache <= 0.9.7.3 - Improper Input Validation via openssl_verify","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-0973-improper-input-validation-via-openssl-verify","description":"W3 Total Cache in versions 0.5 up to 0.9.7.3 does not sufficiently validate the \"openssl_verify\" result in \"\/services\/MessageValidator\/MessageValidator.php\". A remote attacker can create a specially crafted certificate and bypass cryptographic checks.","date":"2019-05-07"}],"impact":[]},{"uuid":"dfb1909e42f7c7fbc315b5beb8390d8e11c5303f4811003c732827cec3ce30b7","name":"W3 Total Cache [w3-total-cache] < 0.9.7.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.7.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d10065940b7560bcc2c3fde42548d084ae67f076","name":"W3 Total Cache plugin <= 0.9.7.3 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-plugin-0973-reflected-cross-site-scripting","description":"The W3 Total Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation on the $command variable, which makes it possible for attackers to inject arbitrary web sites in victims browsers in versions up to, and including, 0.9.7.3.","date":"2019-05-07"}],"impact":[]},{"uuid":"803a86c7f6a67051e14b2a9cde50dadcd22d38bbe04f209c8160150675dc071b","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d473645bbab8ab677705fe4535f09454f537d982","name":"W3 Total Cache <= 0.9.4.1 - Weak validation of Amazon SNS push messages","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-0941-weak-validation-of-amazon-sns-push-messages","description":"The W3 Total Cache plugin for WordPress is vulnerable to weak validation of Amazon SNS push messages in versions up to, and including, 0.9.4.1. This makes it possible for attackers to perform a variety of actions concerning the server's cache, such as performing a Denial of Service attack on the site.","date":"2016-11-10"}],"impact":[]},{"uuid":"3a86881f34e4009d19ed59657f3cffbe31c7926211d57242716d7c265947b80f","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ade6610e45ed3c5100030940d6f2c0eed9bba619","name":"W3 Total Cache <= 0.9.4 - Server-Side Request Forgery leading to Host Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-094-server-side-request-forgery-leading-to-host-information-disclosure","description":"The W3 Total Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 0.9.4. This is due to a minify function incorrectly restricting path input. This makes it possible for attackers to access restricted resources on private networks by using a vulnerable installation as a limited HTTP GET proxy.","date":"2016-10-31"}],"impact":[]},{"uuid":"4eb9434d7a35312feb7444017aba68c83a283de0f1f1a466c05698b9a82cf338","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"93fe3c61a47870bbeb7075d84dd635c1a1fd2b0e","name":"W3 Total Cache <= 0.9.4.1 - Security Token Bypass via Type Juggling","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-0941-security-token-bypass-via-type-juggling","description":"The W3 Total Cache plugin for WordPress is vulnerable to authorization bypass due to the use of loose comparison on the nonce value in the \/pub\/apc.php file. This affects versions up to, and including, 0.9.4.1. This makes it possible for attackers to bypass nonce protections if a valid nonce starts with 0e.  In the right situation this bypass can be used to empty the OPCache.","date":"2016-09-26"}],"impact":[]},{"uuid":"4b1b785cdfa0cc65366a93fa5c9e65e3c17bb9d479b1a3593b221544dc9942ac","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8bbc76fa6332bab2da8c13b6c3951743717967b8","name":"W3 Total Cache <= 0.9.4.1 - Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-0941-arbitrary-file-upload","description":"The W3 Total Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 0.9.4.1. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.","date":"2016-09-26"}],"impact":[]},{"uuid":"8fde612f073017714450ae847005371dbcfbb591e7c92c50940edffe3297a521","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"dc96b31f0157331474aacdc40f3c0d7ac7c77a12","name":"W3 Total Cache <= 0.9.4.1 - Authenticated Arbitrary File Download","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-0941-authenticated-arbitrary-file-download","description":"The W3 Total Cache plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 0.9.4.1 This can allow an administrator attacker to extract sensitive data from wp-config.php that could be used to fully take over the site.","date":"2016-09-26"}],"impact":[]},{"uuid":"adb039f25864fbf799b32b04a227358443a61c6e3a2228a25e8b9d88719c0ff4","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9070d4e77dc9c3bb83729cfa0eb88b9abc5e7f38","name":"W3 Total Cache <= 0.9.4.1 - Arbitrary Code Execution via settings import","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-0941-arbitrary-code-execution-via-settings-import","description":"The W3 Total Cache plugin for WordPress is vulnerable to Authenticated Arbitrary Code Execution via settings import in versions up to, and including, 0.9.4.1. This makes it possible for authenticated attackers to inject and execute arbitrary code.","date":"2016-09-26"}],"impact":[]},{"uuid":"37b52e38ea4bd7e7adc513b02b31ff9abcb04eb5b368e7757ce25af0a14e087a","name":"W3 Total Cache [w3-total-cache] < 0.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f5e6351ff19dc391a2a750b2f7b0f97e716d5b29","name":"W3 Total Cache <= 0.9.4.1 - Cross-Site Scripting via request_id","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-0941-cross-site-scripting-via-request-id","description":"The W3 Total Cache plugin plugin for WordPress is vulnerable to Cross-Site Scripting via the 'request_id' parameter in versions up to, and including, 0.9.4.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2016-07-29"}],"impact":[]},{"uuid":"6bcef03e168ae962d52231390afd61116e2ef1ecd0b8729b1197d399c785b4aa","name":"W3 Total Cache [w3-total-cache] < 0.9.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"440d508939c231b4d88a35a4f78ea3fab258d1d8","name":"W3 Total Cache <= 0.9.4 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-094-cross-site-request-forgery-leading-to-stored-cross-site-scripting","description":"The W3 Total Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.9.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page via forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2014-09-08"}],"impact":[]},{"uuid":"fd603d82b5a055798a962c6ac1c09b4c351ebd5d080f3d4a6b0238cda7c7a575","name":"W3 Total Cache [w3-total-cache] < 2.7.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-5359","name":"CVE-2023-5359","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-5359","description":"[en] The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account information in successful conditions. This would not impact the WordPress users site in any way.","date":"2024-09-24"},{"id":"e921aa498660b99dc5298b53d8c707f1cdb6f966","name":"WordPress W3 Total Cache Plugin <= 2.7.5 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-2-7-5-sensitive-credentials-stored-in-plaintext-vulnerability","description":"<p>WordPress W3 Total Cache Plugin <= 2.7.5 is vulnerable to Sensitive Data Exposure<\/p><p>Software: W3 Total Cache<\/p><p>Link: https:\/\/wordpress.org\/plugins\/w3-total-cache\/#developers<\/p><p>Affected Version <= 2.7.5<\/p><p>Fixed in version 2.7.6 <\/p>","date":"2024-09-24"},{"id":"94beb90ac4ffd16b3f2d423333902d5cdf3765c9","name":"W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-275-sensitive-credentials-stored-in-plaintext","description":"The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account information in successful conditions. This would not impact the WordPress users site in any way.","date":"2024-09-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."},{"cwe":"CWE-312","name":"Cleartext Storage of Sensitive Information","description":"The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6e0e469a86b94f8bfbb8bbbc6b0b4bfdea87f56ddb5495a2205d81fd3c9c056f","name":"W3 Total Cache [w3-total-cache] < 2.8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-12008","name":"CVE-2024-12008","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-12008","description":"[en] The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example, the log file may contain nonce values that can be used in further CSRF attacks.\r\nNote: the debug feature must be enabled for this to be a concern, and it is disabled by default.","date":"2025-01-14"},{"id":"e832fe2510ac2bf395d8f158d7c059ca778a9005","name":"WordPress W3 Total Cache Plugin <= 2.8.1 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/w3-total-cache\/vulnerability\/wordpress-w3-total-cache-plugin-2-8-1-information-exposure-via-log-files-vulnerability","description":"<p>WordPress W3 Total Cache Plugin <= 2.8.1 is vulnerable to Sensitive Data Exposure<\/p><p>Software: W3 Total Cache<\/p><p>Fixed in version 2.8.2 <\/p><p>Affected Version <= 2.8.1<\/p><p>CVE: CVE-2024-12008<\/p>","date":"2025-01-13"},{"id":"826ab31b83c4d5ab34d553aac5a443fab6dd201f","name":"W3 Total Cache <= 2.8.1 Information Exposure via Log Files","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-281-information-exposure-via-log-files","description":"The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example, the log file may contain nonce values that can be used in further CSRF attacks.\r\nNote: the debug feature must be enabled for this to be a concern, and it is disabled by default.","date":"2025-01-13"},{"id":"EUVD-2024-50532","name":"EUVD-2024-50532","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-50532","description":"The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example, the log file may contain nonce values that can be used in further CSRF attacks.\r\nNote: the debug feature must be enabled for this to be a concern, and it is disabled by default.","date":"2025-01-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.099"}},{"uuid":"636d9b0d9c2366dd0187ba9c29a8c9f9f1b4c749d7de778e9313afe8486f1a59","name":"W3 Total Cache [w3-total-cache] < 2.8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-12006","name":"CVE-2024-12006","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-12006","description":"[en] The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin extensions.","date":"2025-01-14"},{"id":"94a9eb1af22d0d44e816262a812dbfe3cfaef40c","name":"W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation\/Deactivation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-281-missing-authorization-to-unauthenticated-plugin-deactivation-and-extensions-activationdeactivation","description":"The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin extensions.","date":"2025-01-13"},{"id":"EUVD-2024-50530","name":"EUVD-2024-50530","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-50530","description":"The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin extensions.","date":"2025-01-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.003"}},{"uuid":"355b1249020a37dfe8990dbde15f1ae0ad51660359a20f3ac19000c88757a704","name":"W3 Total Cache [w3-total-cache] < 2.8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-12365","name":"CVE-2024-12365","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-12365","description":"[en] The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain the plugin's nonce value and perform unauthorized actions, resulting in information disclosure, service plan limits consumption as well as making web requests to arbitrary locations originating from the web application that can be used to query information from internal services, including instance metadata on cloud-based applications.","date":"2025-01-14"},{"id":"4fb3021c39165b040964d0c704864f4fb4578042","name":"W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-281-authenticated-subscriber-missing-authorization-to-server-side-request-forgery","description":"The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain the plugin's nonce value and perform unauthorized actions, resulting in information disclosure, service plan limits consumption as well as making web requests to arbitrary locations originating from the web application that can be used to query information from internal services, including instance metadata on cloud-based applications.","date":"2025-01-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"h","i":"l","a":"n","score":"8.5","severity":"h","exploitable":"3.1","impact":"4.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:L\/A:N","score":"8.5","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"high","i":"low","a":"none","exploitable":"3.1","impact":"4.7"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"515a33baf837833810c79f949d41c8a7d814660c8a669d19c823425eee7de33f","name":"W3 Total Cache [w3-total-cache] < 2.9.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-27384","name":"CVE-2026-27384","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-27384","description":"[en] Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects W3 Total Cache: from n\/a through <= 2.9.1.","date":"2026-03-05"},{"id":"75a8c22db520b6c51a5d52e30a4639ca11185eb6","name":"W3 Total Cache <= 2.9.1 - Unauthenticated Arbitrary Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-291-unauthenticated-arbitrary-code-execution","description":"The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to execute code on the server.","date":"2026-02-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"n","ui":"n","s":"c","c":"h","i":"h","a":"h","score":"9.0","severity":"c","exploitable":"2.2","impact":"6.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H","score":"9.0","severity":"critical","av":"network","ac":"high","pr":"none","ui":"none","s":"changed","c":"high","i":"high","a":"high","exploitable":"2.2","impact":"6.0"},"cwe":[{"cwe":"CWE-1284","name":"Improper Validation of Specified Quantity in Input","description":"The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"f034a3a7fe2bcf52d1acbfd080081aa5f0a46ec7aae04b13062268a590243e02","name":"W3 Total Cache [w3-total-cache] < 2.9.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5032","name":"W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5032","description":"The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains \"W3 Total Cache\", which causes raw mfunc\/mclude dynamic fragment HTML comments \u2014 including the W3TC_DYNAMIC_SECURITY security token \u2014 to be rendered in the page source. This makes it possible for unauthenticated attackers to discover the value of the W3TC_DYNAMIC_SECURITY constant by sending a crafted User-Agent header to any page that contains developer-placed dynamic fragment tags, granted the site has the fragment caching feature enabled. With the leaked W3TC_DYNAMIC_SECURITY token, an attacker can craft valid mfunc tags to execute arbitrary PHP code on the server, achieving remote code execution.","date":"0000-00-00"},{"id":"15dc952db28bc10290eef905f8d9ce7c4e172913","name":"W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-293-unauthenticated-security-token-exposure-via-user-agent-header","description":"The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains \"W3 Total Cache\", which causes raw mfunc\/mclude dynamic fragment HTML comments \u2014 including the W3TC_DYNAMIC_SECURITY security token \u2014 to be rendered in the page source. This makes it possible for unauthenticated attackers to discover the value of the W3TC_DYNAMIC_SECURITY constant by sending a crafted User-Agent header to any page that contains developer-placed dynamic fragment tags, granted the site has the fragment caching feature enabled. With the leaked W3TC_DYNAMIC_SECURITY token, an attacker can craft valid mfunc tags to execute arbitrary PHP code on the server, achieving remote code execution.","date":"2026-04-01"}],"impact":{"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"793888265d17b61560e175609c66b12915e7133187122965599849f8ba2a513e","name":"W3 Total Cache [w3-total-cache] < 2.8.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-9501","name":"W3 Total Cache < 2.8.13 - Unauthenticated Command Injection","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-9501","description":"The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.","date":"0000-00-00"},{"id":"1c2387eb289f003820c676836011eb22ce6d8532","name":"W3 Total Cache <= 2.8.12 - Unauthenticated Command Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-2812-unauthenticated-command-injection","description":"The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.8.12 via _parse_dynamic_mfunc . This makes it possible for unauthenticated attackers to execute code on the server when comments are enabled and a post has been incorrectly injected with the mfunc tags. Please note we consider this to be a theoretical issue, and as such we rejected the original report from the researcher who then submitted this to WPScan. WPScan assigned a CVE ID, but we do not agree that this is a true security vulnerability. Exploitation of this issue is theoretical and requires gaining access to a secret value much like gaining access to a password.","date":"2025-10-27"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"965199c48cd9b5ef585166753605ab57501952c33c82c2d4f4e42d1530947b50","name":"W3 Total Cache [w3-total-cache] < 2.9.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-39595","name":"CVE-2026-39595","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-39595","description":"[en] Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.","date":"2026-06-17"},{"id":"ec0be021f11905c20e4dd62574eff929c6c259d6","name":"W3 Total Cache <= 2.9.1 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-291-missing-authorization","description":"The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with author-level access and above, to perform an unauthorized action.","date":"2026-03-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"4.7","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"4.7","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c8c50ed344f0be4d69d3dbe9c90c08de654e3432a40707d4887f9fa4d0786a60","name":"W3 Total Cache [w3-total-cache] < 2.10.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-57623","name":"CVE-2026-57623","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-57623","description":"[en] Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.","date":"2026-07-02"},{"id":"9e3578d8abfdbc8b746e00f34a6d29f6acc32a86","name":"W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-294-unauthenticated-arbitrary-code-execution","description":"The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.4. This makes it possible for unauthenticated attackers to execute code on the server.","date":"2026-06-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"n","ui":"n","s":"c","c":"h","i":"h","a":"h","score":"9.0","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H","score":"9.0","severity":"critical","av":"network","ac":"high","pr":"none","ui":"none","s":"changed","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-1284","name":"Improper Validation of Specified Quantity in Input","description":"The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"1e3cd66dc4c2d37b4bee804ce9dc67efee354431d76f0333540eba5e73eed863","name":"W3 Total Cache [w3-total-cache] < 2.10.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-9282","name":"CVE-2026-9282","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-9282","description":"[en] The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires enabling manual minify mode and supplying a manual-format minify filename so that the hash is empty and the f_array[] entries are not overwritten before reaching setupSources().","date":"2026-07-11"},{"id":"11ec2bf28aa958f9416663eaf04d02f280cec022","name":"W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/e92cc06d-006f-4bba-a4ef-b23d80c00085","description":"The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires enabling manual minify mode and supplying a manual-format minify filename so that the hash is empty and the f_array[] entries are not overwritten before reaching setupSources().","date":"2026-07-10"},{"id":"37548c3960e1ed6c62709c011ce6dc0365c757f0","name":"W3 Total Cache &lt;= 2.9.4 - Unauthenticated Arbitrary File Read via &#039;f_array[]&#039; Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-294-unauthenticated-arbitrary-file-read-via-f-array-parameter","description":"The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires enabling manual minify mode and supplying a manual-format minify filename so that the hash is empty and the f_array[] entries are not overwritten before reaching setupSources().","date":null},{"id":"EUVD-2026-43164","name":"EUVD-2026-43164","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-43164","description":"The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires enabling manual minify mode and supplying a manual-format minify filename so that the hash is empty and the f_array[] entries are not overwritten before reaching setupSources().","date":"2026-07-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.004"}},{"uuid":"8f764c4baf8aff8943b9510878c26606a3cf978098f4b02e69836ce790113973","name":"W3 Total Cache [w3-total-cache] < 2.10.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-66695","name":"CVE-2026-66695","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-66695","description":"[en] Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.","date":"2026-08-06"},{"id":"00af321cc20db3eb1cd7952d4d55058ac472041f","name":"W3 Total Cache <= 2.10.2 - Unauthenticated Path Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-2102-unauthenticated-path-traversal","description":"The W3 Total Cache plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.10.2. This makes it possible for unauthenticated attackers to perform actions on files outside of the originally intended directory.","date":"2026-07-31"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-35","name":"Path Traversal: '...\/...\/\/'","description":"The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '...\/...\/\/' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory."}]}},{"uuid":"7be2721e5a7038ed3b67b665290b552c4af35701042c8afcfc976932135d0d8e","name":"W3 Total Cache [w3-total-cache] < 2.10.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-18109","name":"CVE-2026-18109","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-18109","description":"[en] The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step.","date":"2026-08-14"},{"id":"1d425f20c9c08b34a811279741fc6b86f04a8018","name":"W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-2103-unauthenticated-stored-cross-site-scripting-via-comment-author-name","description":"The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step.","date":"2026-08-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"04e413765dcdd2dc7a11cc63fd92022e3061b69e550270bf180451aa240001d4","name":"W3 Total Cache [w3-total-cache] < 2.10.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-18051","name":"CVE-2026-18051","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-18051","description":"[en] The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name.\nOn Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.","date":"2026-08-19"},{"id":"a82a6fe2240343834bad3ff2d25d4db7b330a0f3","name":"W3 Total Cache &lt; 2.10.5 - Unauthenticated Path Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-2105-unauthenticated-path-traversal","description":"The W3 Total Cache plugin for WordPress is vulnerable to Path Traversal in all versions up to 2.10.5. This is due to insufficient validation of a user supplied path. This makes it possible for unauthenticated attackers to access files and directories outside of the intended directory.","date":null}],"impact":{"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"5a139984fc7c67da4630637f63c68af84c8c86530aa2fbd5884f141f85ea748c","name":"W3 Total Cache [w3-total-cache] < 2.10.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-78438","name":"CVE-2026-78438","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-78438","description":"[en] The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the \"Lazy Load Images\" feature with \"Process background images\" to be enabled, and the malicious comment to be approved by a moderator before execution is triggered.","date":"2026-09-05"},{"id":"68a4b800d5d6af441a623022cb296674eb9450fd","name":"W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/w3-total-cache\/w3-total-cache-2105-unauthenticated-stored-cross-site-scripting-via-lazyload-background-mutator","description":"The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the \"Lazy Load Images\" feature with \"Process background images\" to be enabled, and the malicious comment to be approved by a moderator before execution is triggered.","date":"2026-08-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1788601847"}