Using this vulnerability, an attacker using a carefully crafted query could insert malicious scripts to the plugin’s cached file listing page. As this page requires a valid nonce in order to be displayed, a successful exploitation would require the site’s administrator to have a look at that particular section, manually.
This vulnerability affects the following application versions:
- WP Supercache 0.9.7
- WP Supercache 0.9.8
- WP Supercache 0.9.9
- WP Supercache 0.9.9.1
- WP Supercache 0.9.9.2
- WP Supercache 0.9.9.3
- WP Supercache 0.9.9.4
- WP Supercache 0.9.9.5
- WP Supercache 0.9.9.6
- WP Supercache 0.9.9.7
- WP Supercache 0.9.9.8
- WP Supercache 0.9.9.9
- WP Supercache 1.0
- WP Supercache 1.1
- WP Supercache 1.2
- WP Supercache 1.3.1
- WP Supercache 1.3.2
- WP Supercache 1.4
- WP Supercache 1.4.1
- WP Supercache 1.4.2