Nginx Cache Purge Preload <= 2.1.1 - Authenticated (Administrator+) Remote Code Execution
highThe Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.1 via the 'nppp_preload_cache_on_update' function. This is due to insufficient sanitization of the $_SERVER['HTTP_REFERERER'] parameter passed from the 'nppp_handle_fastcgi_cache_actions_a...
- CVSS:
- 7.2
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.3
- Disclosed:
- Jul 21, 2025