Extension WordPress
Vulnérabilités WP Super Cache
Cette page rassemble les failles publiées pour WP Super Cache, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Super Cache
12 fiches
WP Super Cache <= 1.8 – Unauthenticated Cache Poisoning
The WP Super Cache plugin for WordPress is vulnerable to Unauthenticated Cache Poisoning in versions up to, and including, 1.8. This is due to insufficient parsing of URLs containing double slashes. This makes it possible for unauthenticated attackers…
*-1.8
1.9
03/10/2022
WP Super Cache <= 1.7.2 – Authenticated Remote Code Execution
The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of…
[*, 1.7.3)
1.7.3
14/05/2021
WP Super Cache <= 1.7.2 – Authenticated (Admin+) Stored Cross-Site Scripting
The Twitter Bootstrap Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_cache_location' parameter in versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
[*, 1.7.3)
1.7.3
12/04/2021
WP Super Cache <= 1.7.1 – Authenticated (Admin+) Remote Code Execution
The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option.…
[*, 1.7.2)
1.7.2
16/03/2021
WP Super Cache <= 1.4.8 – Cross-Site Scripting
The WP Super Cashe plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts…
*-1.4.8
1.4.9
03/02/2017
WP Super Cache <= 1.4.4 – PHP Object Injection
The WP Super Cache plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.4 via deserialization of untrusted input. This allows attackers to inject a PHP Object into cache files. If the…
[*, 1.4.5)
1.4.5
25/09/2015
WP Super Cache <= 1.4.4 – Authenticated File Deletion
The WP Super Cache plugin for WordPress is vulnerable to Authenticated File Deletion in versions up to, and including, 1.4.4. Code that sanitized directory paths when deleting cache files wasn't secure and might allow an attacker to view…
[*, 1.4.5)
1.4.5
25/09/2015
WP Super Cache <= 1.4.4 – Directory Listing
The WP Super Cache plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 1.4.4. This allows unauthenticated attackers to read the contents of arbitrary directories on the server, which can contain sensitive information.
[*, 1.4.5)
1.4.5
25/09/2015
WP Super Cache < 1.4.3 – Cross Site Scripting
The WP Super Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$details[ ‘key’ ]` value in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible…
[*, 1.4.3)
1.4.3
07/04/2015
WP Super Cache <= 1.2 – Remote Code Execution
The WP Super Cache plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.2. This allows unauthenticated attackers to execute code on the server.
*-1.2
1.3
01/08/2014
WP Super Cache < 1.3.2 – Remote Code Execution
WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.
[*, 1.3.2)
1.3.2
01/08/2014
WP Super Cache Plugin <= 1.3 – Multiple Cross-Site Scripting
The WordPress Super Cache Plugin 1.3 has XSS via several vulnerable parameters.
*-1.3
1.3.1
01/08/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.