QID 730116
Date Published: 2021-06-21
QID 730116: WordPress Super Cache WordPress plugin authenticated (admin+) RCE Vulnerability
Wordpress is an open source CMS. The WP Super Cache WordPress plugin affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option.
Affected Versions:
WordPress WP Super Cache plugin Prior to 1.7.2
QID Detection Logic:(Unauthenticated)
It checks for the vulnerable version of the plugin.
Successful exploitation of the RCE means that an attacker can compromise the web application and/or web server.
Solution
Customers are advised to install 1.7.2 or later versions of WP Super Cache to remediate this vulnerability.
Vendor References
CVEs related to QID 730116
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 2496238 |
|