{"error":0,"message":null,"data":{"name":"WP Super Cache","plugin":"wp-super-cache","link":"https:\/\/wordpress.org\/plugins\/wp-super-cache\/","latest":"1787768760","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"84388e8a38348d254afac88dee36c54dfe3846f53bd607fa5df3cdb4395a77ec","name":"WP Super Cache [wp-super-cache] < 1.7.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24329","name":"CVE-2021-24329","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24329","description":"[en] The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.","date":"2021-06-01"},{"id":"ec78e9b172dbf460ba9e2170361d6bde7dc9dcd6","name":"WordPress WP Super Cache plugin <= 1.7.2 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-super-cache\/vulnerability\/wordpress-wp-super-cache-plugin-1-7-2-authenticated-persistent-cross-site-scripting-xss-vulnerability","description":"Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress WP Super Cache plugin (versions <= 1.7.2).","date":"2021-04-28"},{"id":"bf0d1ef1beba660c51de370b99a713ecb8d11b61","name":"WP Super Cache <= 1.7.2 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-super-cache\/wp-super-cache-172-authenticated-admin-stored-cross-site-scripting","description":"The Twitter Bootstrap Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_cache_location' parameter in versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2021-04-12"},{"id":"9df86d05-1408-4c22-af55-5e3d44249fd0","name":"WP Super Cache &lt; 1.7.3 - Authenticated Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/9df86d05-1408-4c22-af55-5e3d44249fd0","description":"The plugin did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"12bdfcc7a81361a391617eee322dc5ebfbc73b3d5c9c1d667c28dec26313bf78","name":"WP Super Cache [wp-super-cache] < 1.7.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24312","name":"CVE-2021-24312","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24312","description":"[en] The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\\n'. This is due to an incomplete fix of CVE-2021-24209.","date":"2021-06-01"},{"id":"aa40a74a7cd04f245d0df813603d01c07d96c15a","name":"WP Super Cache <= 1.7.2 - Authenticated Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-super-cache\/wp-super-cache-172-authenticated-remote-code-execution","description":"The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\\n'. This is due to an incomplete fix of CVE-2021-24209.","date":"2021-05-14"},{"id":"2142c3d3-9a7f-4e3c-8776-d469a355d62f","name":"WP Super Cache &lt; 1.7.3 - Authenticated Remote Code Execution","link":"https:\/\/wpscan.com\/vulnerability\/2142c3d3-9a7f-4e3c-8776-d469a355d62f","description":"The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the plugin settings result in RCE because they allow input of &quot;$&quot; and &quot;\\n&quot;. This is due to an incomplete fix of CVE-2021-24209.\r\n\r\nYou can run the command directly to &quot;https:\/\/target\/wp-content\/wp-cache-config.php&quot;.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-78","name":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","description":"The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component."},{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}]}},{"uuid":"073a0f533601fb6e95d90b4001e12e0b7b1cdfe4d3f9b12a645b37e3e37af483","name":"WP Super Cache [wp-super-cache] < 1.7.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24209","name":"CVE-2021-24209","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24209","description":"[en] The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.","date":"2021-04-05"},{"id":"f84e99b1a2730ec143ccbc9a8dc698de46ca6c6e","name":"WordPress WP Super Cache plugin <= 1.7.1 - Authenticated Remote Code Execution (RCE) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-super-cache\/vulnerability\/wordpress-wp-super-cache-plugin-1-7-1-authenticated-remote-code-execution-rce-vulnerability","description":"Authenticated Remote Code Execution (RCE) vulnerability (settings page) discovered by m0ze (Patchstack Red Team) in WordPress WP Super Cache plugin (versions <= 1.7.1).","date":"2021-03-16"},{"id":"0aa7bf76a20f69b2a6f210ef9dfec02b2791f926","name":"WP Super Cache <= 1.7.1 - Authenticated (Admin+) Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-super-cache\/wp-super-cache-171-authenticated-admin-remote-code-execution","description":"The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.","date":"2021-03-16"},{"id":"733d8a02-0d44-4b78-bbb2-37e447acd2f3","name":"WP Super Cache &lt; 1.7.2 - Authenticated Remote Code Execution (RCE)","link":"https:\/\/wpscan.com\/vulnerability\/733d8a02-0d44-4b78-bbb2-37e447acd2f3","description":"The plugin was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -&gt; Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.\r\n\r\nAnother possible attack vector: from XSS (via another plugin affected by XSS) to RCE.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}]}},{"uuid":"5e9ad8956c43deb99c39b5c26aa4db975c5463cac51543e29f334cc1574ef7c8","name":"WP Super Cache [wp-super-cache] < 1.3.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2013-2009","name":"CVE-2013-2009","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2013-2009","description":"[en] WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution","date":"2020-02-07"},{"id":"0a5748c747c3ff4d6805b43a3e6715b8afbfe271","name":"WP Super Cache <= 1.2 - Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-super-cache\/wp-super-cache-12-remote-code-execution","description":"The WP Super Cache plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.2. This allows unauthenticated attackers to execute code on the server.","date":"2014-08-01"},{"id":"eb7d1384-a508-4181-b88c-cbd574506713","name":"WP-Super-Cache 1.3 - Remote Code Execution","link":"https:\/\/wpscan.com\/vulnerability\/eb7d1384-a508-4181-b88c-cbd574506713","description":"The WP Super Cache WordPress plugin was affected by a Remote Code Execution security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"}}},{"uuid":"23d1afcd571d808b9e8d1ba9fe55be55fdfc9021f11ac3cacdda9da7023e3379","name":"WP Super Cache [wp-super-cache] < 1.3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2013-2008","name":"CVE-2013-2008","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2013-2008","description":"[en] WordPress Super Cache Plugin 1.3 has XSS.","date":"2020-02-07"},{"id":"fc7a62ea001e6eeb119bfd93ebe036a35ab276e9","name":"WordPress Super Cache Plugin <= 1.3 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-super-cache\/vulnerability\/wordpress-super-cache-plugin-1-3-xss","description":"This plugin is prone to:\r\ntrunk\/plugins\/wptouch.php URI XSS,\r\n trunk\/plugins\/searchengine.php URI XSS,\r\ntrunk\/plugins\/domain-mapping.php URI XSS,\r\ntrunk\/plugins\/badbehaviour.php URI XSS,\r\ntrunk\/plugins\/awaitingmoderation.php URI XSS,\r\ntrunk\/wp-cache.php wp_nonce_url Function URI XSS vulnerability.\nUpdate the plugin.","date":"2015-05-15"},{"id":"7dc982627ca1c20f6df6c94e3e1e7ac89b4e4f28","name":"WP Super Cache Plugin <= 1.3 - Multiple Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-super-cache\/wp-super-cache-plugin-13-multiple-cross-site-scripting","description":"The WordPress Super Cache Plugin 1.3 has XSS via several vulnerable parameters.","date":"2014-08-01"},{"id":"b80aea2c-ef22-42af-8114-11483fbdd374","name":"WP Super Cache 1.3 - trunk\/plugins\/awaitingmoderation.php URI XSS","link":"https:\/\/wpscan.com\/vulnerability\/b80aea2c-ef22-42af-8114-11483fbdd374","description":"The WP Super Cache WordPress plugin was affected by a trunk\/plugins\/awaitingmoderation.php URI XSS security vulnerability.","date":null},{"id":"955bc84d-70ed-488c-8b96-ad94034649f0","name":"WP Super Cache 1.3 - trunk\/plugins\/badbehaviour.php URI XSS","link":"https:\/\/wpscan.com\/vulnerability\/955bc84d-70ed-488c-8b96-ad94034649f0","description":"The WP Super Cache WordPress plugin was affected by a trunk\/plugins\/badbehaviour.php URI XSS security vulnerability.","date":null},{"id":"2ea440ae-1e33-4149-9eba-fc142f1585f7","name":"WP Super Cache 1.3 - trunk\/plugins\/domain-mapping.php URI XSS","link":"https:\/\/wpscan.com\/vulnerability\/2ea440ae-1e33-4149-9eba-fc142f1585f7","description":"The WP Super Cache WordPress plugin was affected by a trunk\/plugins\/domain-mapping.php URI XSS security vulnerability.","date":null},{"id":"08d7198d-3ec4-43ba-b5b0-8e6d9435fc81","name":"WP Super Cache 1.3 - trunk\/plugins\/searchengine.php URI XSS","link":"https:\/\/wpscan.com\/vulnerability\/08d7198d-3ec4-43ba-b5b0-8e6d9435fc81","description":"The WP Super Cache WordPress plugin was affected by a trunk\/plugins\/searchengine.php URI XSS security vulnerability.","date":null},{"id":"66dcf125-6acb-44fb-b945-a545335f2dcf","name":"WP Super Cache 1.3 - trunk\/plugins\/wptouch.php URI XSS","link":"https:\/\/wpscan.com\/vulnerability\/66dcf125-6acb-44fb-b945-a545335f2dcf","description":"The WP Super Cache WordPress plugin was affected by a trunk\/plugins\/wptouch.php URI XSS security vulnerability.","date":null},{"id":"d98760cf-1b34-4bcc-9afe-ce56d8e11cda","name":"WP Super Cache 1.3 - trunk\/wp-cache.php wp_nonce_url Function URI XSS","link":"https:\/\/wpscan.com\/vulnerability\/d98760cf-1b34-4bcc-9afe-ce56d8e11cda","description":"The WP Super Cache WordPress plugin was affected by a trunk\/wp-cache.php wp_nonce_url Function URI XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"87c12e5ceef3a0d2e252d1b91f29f71e530225e0746f3866c382d07c0cc29226","name":"WP Super Cache [wp-super-cache] < 1.3.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2013-2011","name":"CVE-2013-2011","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2013-2011","description":"[en] WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.","date":"2019-12-26"},{"id":"bd9b8fba361d231f777b01774c9b3019b202c144","name":"WP Super Cache < 1.3.2 - Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-super-cache\/wp-super-cache-132-remote-code-execution","description":"WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.","date":"2014-08-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-116","name":"Improper Encoding or Escaping of Output","description":"The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved."}]}},{"uuid":"22a8df67b13a8d8dd9d109f0f5cb491e27cc545983fe6e1ad40c48977a848dee","name":"WP Super Cache [wp-super-cache] < 1.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"dd07b21a1e5d8f03666b149f3c7be82b52bbbf66","name":"WordPress Super Cache Plugin <= 1.4.4 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-super-cache\/vulnerability\/wordpress-super-cache-plugin-1-4-4-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2015-09-26"}],"impact":[]},{"uuid":"b28039f3e2cf0c7ca975cf0cf7d725a322cf45a34acb13122204e9b74919a4b0","name":"WP Super Cache [wp-super-cache] < 1.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"79cdb4810f4ec862033ca7b7cf12bb1969524d11","name":"WordPress Super Cache Plugin <= 1.4.4 - PHP Object Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-super-cache\/vulnerability\/wordpress-super-cache-plugin-1-4-4-php-object-injection","description":"This plugin is prone to PHP object injection vulnerability.\nUpdate the plugin.","date":"2015-09-26"}],"impact":[]},{"uuid":"0f62f5811d518b470f11ef17d65236610ad46f7ab804a17651f8befb8fa33701","name":"WP Super Cache [wp-super-cache] < 1.4.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"83d274d9b3b869e04453513f1e36962cd976fc68","name":"WordPress Super Cache Plugin <= 1.4.2 - Stored Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-super-cache\/vulnerability\/wordpress-super-cache-plugin-1-4-2-stored-cross-site-scripting","description":"This plugin is prone to a cross site scripting vulnerability\nUpdate the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"aa479f9eee49051be29e199f6dafc6f3382d040bcc7b0a397910f7451563efe6","name":"WP Super Cache [wp-super-cache] < 1.3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1b29bf920e2347e3370de01c7968ee9e176888da","name":"WordPress Super Cache Plugin <= 1.3 - Remote Code Execution","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-super-cache\/vulnerability\/wordpress-super-cache-plugin-1-3-remote-code-execution","description":"This plugin is prone to a remote code execution vulnerability.\nUpdate the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"461ca88e6b36ed4ac9473a97e54772203a042b82e587875a0a30380ab0367924","name":"WP Super Cache [wp-super-cache] < 1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"291717aa87fea8892f391df0755bf84311890963","name":"WordPress WP Super Cache Plugin - Remote PHP Code Execution","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-super-cache\/vulnerability\/wordpress-wp-super-cache-plugin-remote-php-code-execution","description":"WP Super Cache plugins is prone to remote PHP code-execution vulnerability. It allows an attacker to execute arbitrary PHP code within the context of the web server.\nUpdate the plugin.","date":"2013-04-24"}],"impact":[]},{"uuid":"bd4a99229deeecbb0595f3292ffa2b769a943d6cc94861d69af0ddaafac1761b","name":"WP Super Cache [wp-super-cache] < 1.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e65f8a2570684af84ab29a66f3d10b6494147052","name":"WordPress WP Super Cache plugin <= 1.8 - Cache Poisoning vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-super-cache\/vulnerability\/wordpress-wp-super-cache-plugin-1-8-cache-poisoning-vulnerability","description":"Cache Poisoning vulnerability discovered in WordPress WP Super Cache plugin (versions <= 1.8).\nUpdate the WordPress WP Super Cache plugin to the latest available version (at least 1.9).","date":"2022-10-03"}],"impact":[]},{"uuid":"7527085ff0d471a7debf6a8713c603cac1f3862df6277d36da836774960512f8","name":"WP Super Cache [wp-super-cache] < 1.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c8a3f87d9ce8b5f42769734092f9f342fbea9de8","name":"WP Super Cache <= 1.8 - Unauthenticated Cache Poisoning","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-super-cache\/wp-super-cache-18-unauthenticated-cache-poisoning","description":"The WP Super Cache plugin for WordPress is vulnerable to Unauthenticated Cache Poisoning in versions up to, and including, 1.8. This is due to insufficient parsing of URLs containing double slashes. This makes it possible for unauthenticated attackers to poison the site's cache potentially resulting in harmful content being served to visitors.","date":"2022-10-03"}],"impact":[]},{"uuid":"997d4b4956354ff3a909a7f55b161f80a42aea7380ffe4c2be8e462db7dc336e","name":"WP Super Cache [wp-super-cache] < 1.4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0ee53d9649fe16571ef4e762b541936157007703","name":"WP Super Cache <= 1.4.8 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-super-cache\/wp-super-cache-148-cross-site-scripting","description":"The WP Super Cashe plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2017-02-03"}],"impact":[]},{"uuid":"64658a4f2f13ad1fb5592f49151376d7854d13dfee0738050f0d007c832644a0","name":"WP Super Cache [wp-super-cache] < 1.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"398214c3457f58d3c42c9b2f824e3da0bb76ba9a","name":"WP Super Cache <= 1.4.4 - Directory Listing","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-super-cache\/wp-super-cache-144-directory-listing","description":"The WP Super Cache plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 1.4.4. This allows unauthenticated attackers to read the contents of arbitrary directories on the server, which can contain sensitive information.","date":"2015-09-25"}],"impact":[]},{"uuid":"822eb8c8780d41c4193513cb3f3715f4bd08a0174a25b4cb4ff026ae7a7b15a1","name":"WP Super Cache [wp-super-cache] < 1.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"43bcb64c982f04582dc01eb288ff44b4cfc0bc39","name":"WP Super Cache <= 1.4.4 - Authenticated File Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-super-cache\/wp-super-cache-144-authenticated-file-deletion","description":"The WP Super Cache plugin for WordPress is vulnerable to Authenticated File Deletion in versions up to, and including, 1.4.4. Code that sanitized directory paths when deleting cache files wasn't secure and might allow an attacker to view or delete files named index.html. This makes it possible for authenticated attackers to delete some index files, which can lead to some site accessibility issues and information disclosure.","date":"2015-09-25"}],"impact":[]},{"uuid":"191aaebdae4e250ecb5a788a91d9e16387e30e080f4cb7e34057e2a8a621364c","name":"WP Super Cache [wp-super-cache] < 1.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c70b5c107c2a4a5e514363edc507a94735cdb7ef","name":"WP Super Cache <= 1.4.4 - PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-super-cache\/wp-super-cache-144-php-object-injection","description":"The WP Super Cache plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.4 via deserialization of untrusted input. This allows attackers to inject a PHP Object into cache files. If the cache file is accessed, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2015-09-25"}],"impact":[]},{"uuid":"61aeaef9deb359c64d0a37c25b2bea62c90e769f3e00ed4986f7b16a12cceff4","name":"WP Super Cache [wp-super-cache] < 1.4.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"668810ebdc106dd2c5ed3f93a450096cec74f4a8","name":"WP Super Cache < 1.4.3 - Cross Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-super-cache\/wp-super-cache-143-cross-site-scripting","description":"The WP Super Cache  plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$details[ \u2018key\u2019 ]` value in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2015-04-07"}],"impact":[]},{"uuid":"e159b06f2b05de8c256481ba40203acda4cd1817729982adc9643f96efdc2851","name":"WP Super Cache [wp-super-cache] < 1.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f9dddb51-60ff-4fed-8c89-749d92c4af94","name":"WP Super Cache &lt; 1.9 - Unauthenticated Cache Poisoning","link":"https:\/\/wpscan.com\/vulnerability\/f9dddb51-60ff-4fed-8c89-749d92c4af94","description":"The plugin is affected by a cache poisoning issue","date":null}],"impact":[]},{"uuid":"b6586bc6086cb88f93d89f57a96d9c3a5705e7db159ad2ec3a6cf20eee77ef76","name":"WP Super Cache [wp-super-cache] < 1.4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fcad24bc-876e-4452-bca4-a072f8e86a02","name":"WP Super Cache &lt; 1.4.9 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/fcad24bc-876e-4452-bca4-a072f8e86a02","description":"The WP Super Cache WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"e8e8045750981999a9f4ae28a4b872551e2497615f61fbe31f8dbb437dbd1e0a","name":"WP Super Cache [wp-super-cache] < 1.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e3c7dc0a-fd8b-4057-a049-ac9100f590f9","name":"WP Super Cache &lt; 1.4.5 - PHP Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/e3c7dc0a-fd8b-4057-a049-ac9100f590f9","description":"The WP Super Cache WordPress plugin was affected by a PHP Object Injection security vulnerability.","date":null}],"impact":[]},{"uuid":"9474b985c51a76bf0d62b390b47a83b1bb1ba308c8b27852ae9cfbd9a621c34a","name":"WP Super Cache [wp-super-cache] < 1.4.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b224d46b-37f1-41c1-b332-42d4a408d125","name":"WP Super Cache &lt; 1.4.3 - Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/b224d46b-37f1-41c1-b332-42d4a408d125","description":"The WP Super Cache WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]}]},"updated":"1776563733"}