WP Super Cache <= 1.8 - Unauthenticated Cache Poisoning
medium
The WP Super Cache plugin for WordPress is vulnerable to Unauthenticated Cache Poisoning in versions up to, and including, 1.8. This is due to insufficient parsing of URLs containing double slashes. This makes it possible for unauthenticated attackers to poison the site's cache potentially resulting in harmful content...
- CVSS:
- 6.5
- Affected:
- up to 1.8
- Fixed in:
- 1.9
- Disclosed:
- Oct 3, 2022
WP Super Cache [wp-super-cache] < 1.9
unknown
The WP Super Cache plugin for WordPress is vulnerable to Unauthenticated Cache Poisoning in versions up to, and including, 1.8. This is due to insufficient parsing of URLs containing double slashes. This makes it possible for unauthenticated attackers to poison the site's cache potentially resulting in harmful content...
- Affected:
- up to 1.9
- Fixed in:
- 1.9
- Disclosed:
- Oct 3, 2022
WP Super Cache [wp-super-cache] < 1.9
unknown
Cache Poisoning vulnerability discovered in WordPress WP Super Cache plugin (versions <= 1.8).
Update the WordPress WP Super Cache plugin to the latest available version (at least 1.9).
- Affected:
- up to 1.9
- Fixed in:
- 1.9
- Disclosed:
- Oct 3, 2022
WP Super Cache [wp-super-cache] < 1.7.3
unknown
[en] The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209.
- Affected:
- up to 1.7.3
- Fixed in:
- 1.7.3
- Disclosed:
- Jun 1, 2021
CVE-2021-24312 on NVD →
WP Super Cache [wp-super-cache] < 1.7.3
unknown
[en] The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.
- Affected:
- up to 1.7.3
- Fixed in:
- 1.7.3
- Disclosed:
- Jun 1, 2021
CVE-2021-24329 on NVD →
WP Super Cache <= 1.7.2 - Authenticated Remote Code Execution
high
The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209.
- CVSS:
- 7.2
- Affected:
- up to 1.7.3
- Fixed in:
- 1.7.3
- Disclosed:
- May 14, 2021
CVE-2021-24312 on NVD →
WP Super Cache <= 1.7.2 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Twitter Bootstrap Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_cache_location' parameter in versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permission...
- CVSS:
- 4.8
- Affected:
- up to 1.7.3
- Fixed in:
- 1.7.3
- Disclosed:
- Apr 12, 2021
CVE-2021-24329 on NVD →
WP Super Cache [wp-super-cache] < 1.7.2
unknown
[en] The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerabil...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Apr 5, 2021
CVE-2021-24209 on NVD →
WP Super Cache <= 1.7.1 - Authenticated (Admin+) Remote Code Execution
high
The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability c...
- CVSS:
- 7.2
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 16, 2021
CVE-2021-24209 on NVD →
WP Super Cache [wp-super-cache] < 1.3.2
unknown
[en] WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Feb 7, 2020
CVE-2013-2009 on NVD →
WP Super Cache [wp-super-cache] < 1.3.1
unknown
[en] WordPress Super Cache Plugin 1.3 has XSS.
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- Feb 7, 2020
CVE-2013-2008 on NVD →
WP Super Cache [wp-super-cache] < 1.3.2
unknown
[en] WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Dec 26, 2019
CVE-2013-2011 on NVD →
WP Super Cache <= 1.4.8 - Cross-Site Scripting
medium
The WP Super Cashe plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 5.3
- Affected:
- up to 1.4.8
- Fixed in:
- 1.4.9
- Disclosed:
- Feb 3, 2017
WP Super Cache [wp-super-cache] < 1.4.9
unknown
The WP Super Cashe plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.4.9
- Fixed in:
- 1.4.9
- Disclosed:
- Feb 3, 2017
WP Super Cache [wp-super-cache] < 1.4.5
unknown
This plugin is prone to PHP object injection vulnerability.
Update the plugin.
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Sep 26, 2015
WP Super Cache [wp-super-cache] < 1.4.5
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Sep 26, 2015
WP Super Cache <= 1.4.4 - PHP Object Injection
high
The WP Super Cache plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.4 via deserialization of untrusted input. This allows attackers to inject a PHP Object into cache files. If the cache file is accessed, it could allow the attacker to delete arbitrary files, retrieve sens...
- CVSS:
- 8.1
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Sep 25, 2015
WP Super Cache <= 1.4.4 - Authenticated File Deletion
medium
The WP Super Cache plugin for WordPress is vulnerable to Authenticated File Deletion in versions up to, and including, 1.4.4. Code that sanitized directory paths when deleting cache files wasn't secure and might allow an attacker to view or delete files named index.html. This makes it possible for authenticated attacke...
- CVSS:
- 5.4
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Sep 25, 2015
WP Super Cache <= 1.4.4 - Directory Listing
medium
The WP Super Cache plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 1.4.4. This allows unauthenticated attackers to read the contents of arbitrary directories on the server, which can contain sensitive information.
- CVSS:
- 5.3
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Sep 25, 2015
WP Super Cache [wp-super-cache] < 1.4.5
unknown
The WP Super Cache plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 1.4.4. This allows unauthenticated attackers to read the contents of arbitrary directories on the server, which can contain sensitive information.
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Sep 25, 2015
WP Super Cache [wp-super-cache] < 1.4.5
unknown
The WP Super Cache plugin for WordPress is vulnerable to Authenticated File Deletion in versions up to, and including, 1.4.4. Code that sanitized directory paths when deleting cache files wasn't secure and might allow an attacker to view or delete files named index.html. This makes it possible for authenticated attacke...
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Sep 25, 2015
WP Super Cache [wp-super-cache] < 1.4.5
unknown
The WP Super Cache plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.4 via deserialization of untrusted input. This allows attackers to inject a PHP Object into cache files. If the cache file is accessed, it could allow the attacker to delete arbitrary files, retrieve sens...
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Sep 25, 2015
WP Super Cache [wp-super-cache] < 1.4.3
unknown
This plugin is prone to a cross site scripting vulnerability
Update the plugin.
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- May 15, 2015
WP Super Cache [wp-super-cache] < 1.3.1
unknown
This plugin is prone to a remote code execution vulnerability.
Update the plugin.
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- May 15, 2015
WP Super Cache < 1.4.3 - Cross Site Scripting
high
The WP Super Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$details[ ‘key’ ]` value in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute when...
- CVSS:
- 7.2
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Apr 7, 2015
WP Super Cache [wp-super-cache] < 1.4.3
unknown
The WP Super Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$details[ ‘key’ ]` value in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute when...
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Apr 7, 2015
WP Super Cache < 1.3.2 - Remote Code Execution
critical
WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.
- CVSS:
- 9.8
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Aug 1, 2014
CVE-2013-2011 on NVD →
WP Super Cache <= 1.2 - Remote Code Execution
high
The WP Super Cache plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.2. This allows unauthenticated attackers to execute code on the server.
- CVSS:
- 8.8
- Affected:
- up to 1.2
- Fixed in:
- 1.3
- Disclosed:
- Aug 1, 2014
CVE-2013-2009 on NVD →
WP Super Cache Plugin <= 1.3 - Multiple Cross-Site Scripting
medium
The WordPress Super Cache Plugin 1.3 has XSS via several vulnerable parameters.
- CVSS:
- 6.1
- Affected:
- up to 1.3
- Fixed in:
- 1.3.1
- Disclosed:
- Aug 1, 2014
CVE-2013-2008 on NVD →
WP Super Cache [wp-super-cache] < 1.3
unknown
WP Super Cache plugins is prone to remote PHP code-execution vulnerability. It allows an attacker to execute arbitrary PHP code within the context of the web server.
Update the plugin.
- Affected:
- up to 1.3
- Fixed in:
- 1.3
- Disclosed:
- Apr 24, 2013
WP Super Cache [wp-super-cache] < 1.9
unknown
The plugin is affected by a cache poisoning issue
- Affected:
- up to 1.9
- Fixed in:
- 1.9
WP Super Cache [wp-super-cache] < 1.4.9
unknown
The WP Super Cache WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.4.9
- Fixed in:
- 1.4.9
WP Super Cache [wp-super-cache] < 1.4.5
unknown
The WP Super Cache WordPress plugin was affected by a PHP Object Injection security vulnerability.
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
WP Super Cache [wp-super-cache] < 1.4.3
unknown
The WP Super Cache WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database