Using this vulnerability, an attacker using a carefully crafted query could insert malicious scripts to the plugin’s cached file listing page. As this page requires a valid nonce in order to be displayed, a successful exploitation would require the site’s administrator to have a look at that particular section, manually.

This vulnerability affects the following application versions:

  • WP Supercache 0.9.7
  • WP Supercache 0.9.8
  • WP Supercache 0.9.9
  • WP Supercache 0.9.9.1
  • WP Supercache 0.9.9.2
  • WP Supercache 0.9.9.3
  • WP Supercache 0.9.9.4
  • WP Supercache 0.9.9.5
  • WP Supercache 0.9.9.6
  • WP Supercache 0.9.9.7
  • WP Supercache 0.9.9.8
  • WP Supercache 0.9.9.9
  • WP Supercache 1.0
  • WP Supercache 1.1
  • WP Supercache 1.2
  • WP Supercache 1.3.1
  • WP Supercache 1.3.2
  • WP Supercache 1.4
  • WP Supercache 1.4.1
  • WP Supercache 1.4.2

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *