Extension WordPress
Vulnérabilités W3 Total Cache, page 2
Cette page rassemble les failles publiées pour W3 Total Cache, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de W3 Total Cache
32 fiches
W3 Total Cache <= 0.9.7.3 – Improper Input Validation via openssl_verify
W3 Total Cache in versions 0.5 up to 0.9.7.3 does not sufficiently validate the "openssl_verify" result in "/services/MessageValidator/MessageValidator.php". A remote attacker can create a specially crafted certificate and bypass cryptographic checks.
*-0.9.7.3
0.9.7.4
07/05/2019
W3 Total Cache <= 0.9.4.1 – Weak validation of Amazon SNS push messages
The W3 Total Cache plugin for WordPress is vulnerable to weak validation of Amazon SNS push messages in versions up to, and including, 0.9.4.1. This makes it possible for attackers to perform a variety of actions concerning the…
*-0.9.4.1
0.9.5
10/11/2016
W3 Total Cache <= 0.9.4 – Server-Side Request Forgery leading to Host Information Disclosure
The W3 Total Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 0.9.4. This is due to a minify function incorrectly restricting path input. This makes it possible for attackers to…
*-0.9.4
0.9.5
31/10/2016
W3 Total Cache <= 0.9.4.1 – Arbitrary Code Execution via settings import
The W3 Total Cache plugin for WordPress is vulnerable to Authenticated Arbitrary Code Execution via settings import in versions up to, and including, 0.9.4.1. This makes it possible for authenticated attackers to inject and execute arbitrary code.
*-0.9.4.1
0.9.5
26/09/2016
W3 Total Cache <= 0.9.4.1 – Authenticated Arbitrary File Download
The W3 Total Cache plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 0.9.4.1 This can allow an administrator attacker to extract sensitive data from wp-config.php that could be used to fully…
*-0.9.4.1
0.9.5
26/09/2016
W3 Total Cache <= 0.9.4.1 – Arbitrary File Upload
The W3 Total Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 0.9.4.1. This makes it possible for authenticated attackers to upload arbitrary files on…
*-0.9.4.1
0.9.5
26/09/2016
W3 Total Cache <= 0.9.4.1 – Security Token Bypass via Type Juggling
The W3 Total Cache plugin for WordPress is vulnerable to authorization bypass due to the use of loose comparison on the nonce value in the /pub/apc.php file. This affects versions up to, and including, 0.9.4.1. This makes it…
*-0.9.4.1
0.9.5
26/09/2016
W3 Total Cache <= 0.9.4.1 – Cross-Site Scripting via request_id
The W3 Total Cache plugin plugin for WordPress is vulnerable to Cross-Site Scripting via the 'request_id' parameter in versions up to, and including, 0.9.4.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers…
*-0.9.4.1
0.9.5
29/07/2016
W3 Total Cache <= 0.9.4 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the "Cache key" in the HTML-Comments, as demonstrated…
*-0.9.4
0.9.4.1
16/12/2014
W3 Total Cache <= 0.9.4 – Cross-Site Request Forgery
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile…
*-0.9.4
0.9.4.1
10/12/2014
W3 Total Cache <= 0.9.4 – Cross-Site Request Forgery leading to Stored Cross-Site Scripting
The W3 Total Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.9.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever…
*-0.9.4
0.9.4.1
08/09/2014
W3 Total Cache <= 0.9.2.8 – Remote Code Execution
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
*-0.9.2.8
0.9.2.9
01/08/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.