Vulnerabilities and security researches forwp-super-cache wp-super-cache
Direction: descendingJun 16, 2026
WP Super Cache # dd07b21a1e5d8f03666b149f3c7be82b52bbbf66
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 26, 2015
- Research Description
- WP Super Cache [wp-super-cache] < 1.4.5 WordPress Super Cache Plugin <= 1.4.4 - Cross Site Scripting Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
- Affected versions
-
max 1.4.5.
- Status
-
vulnerable
WP Super Cache # c70b5c107c2a4a5e514363edc507a94735cdb7ef
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 25, 2015
- Research Description
- WP Super Cache [wp-super-cache] < 1.4.5 WP Super Cache <= 1.4.4 - PHP Object Injection The WP Super Cache plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.4 via deserialization of untrusted input. This allows attackers to inject a PHP Object into cache files. If the cache file is accessed, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
- Affected versions
-
max 1.4.5.
- Status
-
vulnerable
WP Super Cache # 79cdb4810f4ec862033ca7b7cf12bb1969524d11
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 26, 2015
- Research Description
- WP Super Cache [wp-super-cache] < 1.4.5 WordPress Super Cache Plugin <= 1.4.4 - PHP Object Injection This plugin is prone to PHP object injection vulnerability. Update the plugin.
- Affected versions
-
max 1.4.5.
- Status
-
vulnerable
WP Super Cache # 0ee53d9649fe16571ef4e762b541936157007703
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 03, 2017
- Research Description
- WP Super Cache [wp-super-cache] < 1.4.9 WP Super Cache <= 1.4.8 - Cross-Site Scripting The WP Super Cashe plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected versions
-
max 1.4.9.
- Status
-
vulnerable
WP Super Cache # 668810ebdc106dd2c5ed3f93a450096cec74f4a8
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 07, 2015
- Research Description
- WP Super Cache [wp-super-cache] < 1.4.3 WP Super Cache < 1.4.3 - Cross Site Scripting The WP Super Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$details[ ‘key’ ]` value in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.4.3.
- Status
-
vulnerable
WP Super Cache # 291717aa87fea8892f391df0755bf84311890963
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 24, 2013
- Research Description
- WP Super Cache [wp-super-cache] < 1.3 WordPress WP Super Cache Plugin - Remote PHP Code Execution WP Super Cache plugins is prone to remote PHP code-execution vulnerability. It allows an attacker to execute arbitrary PHP code within the context of the web server. Update the plugin.
- Affected versions
-
max 1.3.
- Status
-
vulnerable
WP Super Cache # e65f8a2570684af84ab29a66f3d10b6494147052
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 03, 2022
- Research Description
- WP Super Cache [wp-super-cache] < 1.9 WordPress WP Super Cache plugin <= 1.8 - Cache Poisoning vulnerability Cache Poisoning vulnerability discovered in WordPress WP Super Cache plugin (versions <= 1.8). Update the WordPress WP Super Cache plugin to the latest available version (at least 1.9).
- Affected versions
-
max 1.9.
- Status
-
vulnerable
WP Super Cache # 1b29bf920e2347e3370de01c7968ee9e176888da
- CVE, Research URL
- Home page URL
- Application
- Date
- May 15, 2015
- Research Description
- WP Super Cache [wp-super-cache] < 1.3.1 WordPress Super Cache Plugin <= 1.3 - Remote Code Execution This plugin is prone to a remote code execution vulnerability. Update the plugin.
- Affected versions
-
max 1.3.1.
- Status
-
vulnerable
WP Super Cache # 43bcb64c982f04582dc01eb288ff44b4cfc0bc39
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 25, 2015
- Research Description
- WP Super Cache [wp-super-cache] < 1.4.5 WP Super Cache <= 1.4.4 - Authenticated File Deletion The WP Super Cache plugin for WordPress is vulnerable to Authenticated File Deletion in versions up to, and including, 1.4.4. Code that sanitized directory paths when deleting cache files wasn't secure and might allow an attacker to view or delete files named index.html. This makes it possible for authenticated attackers to delete some index files, which can lead to some site accessibility issues and information disclosure.
- Affected versions
-
max 1.4.5.
- Status
-
vulnerable
WP Super Cache # c8a3f87d9ce8b5f42769734092f9f342fbea9de8
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 03, 2022
- Research Description
- WP Super Cache [wp-super-cache] < 1.9 WP Super Cache <= 1.8 - Unauthenticated Cache Poisoning The WP Super Cache plugin for WordPress is vulnerable to Unauthenticated Cache Poisoning in versions up to, and including, 1.8. This is due to insufficient parsing of URLs containing double slashes. This makes it possible for unauthenticated attackers to poison the site's cache potentially resulting in harmful content being served to visitors.
- Affected versions
-
max 1.9.
- Status
-
vulnerable
WP Super Cache # f9dddb51-60ff-4fed-8c89-749d92c4af94
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Super Cache [wp-super-cache] < 1.9 WP Super Cache < 1.9 - Unauthenticated Cache Poisoning The plugin is affected by a cache poisoning issue
- Affected versions
-
max 1.9.
- Status
-
vulnerable
WP Super Cache # 398214c3457f58d3c42c9b2f824e3da0bb76ba9a
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 25, 2015
- Research Description
- WP Super Cache [wp-super-cache] < 1.4.5 WP Super Cache <= 1.4.4 - Directory Listing The WP Super Cache plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 1.4.4. This allows unauthenticated attackers to read the contents of arbitrary directories on the server, which can contain sensitive information.
- Affected versions
-
max 1.4.5.
- Status
-
vulnerable
WP Super Cache # 83d274d9b3b869e04453513f1e36962cd976fc68
- CVE, Research URL
- Home page URL
- Application
- Date
- May 15, 2015
- Research Description
- WP Super Cache [wp-super-cache] < 1.4.3 WordPress Super Cache Plugin <= 1.4.2 - Stored Cross Site Scripting This plugin is prone to a cross site scripting vulnerability Update the plugin.
- Affected versions
-
max 1.4.3.
- Status
-
vulnerable
WP Super Cache # e3c7dc0a-fd8b-4057-a049-ac9100f590f9
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Super Cache [wp-super-cache] < 1.4.5 WP Super Cache < 1.4.5 - PHP Object Injection The WP Super Cache WordPress plugin was affected by a PHP Object Injection security vulnerability.
- Affected versions
-
max 1.4.5.
- Status
-
vulnerable
WP Super Cache # b224d46b-37f1-41c1-b332-42d4a408d125
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Super Cache [wp-super-cache] < 1.4.3 WP Super Cache < 1.4.3 - Stored Cross-Site Scripting (XSS) The WP Super Cache WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.
- Affected versions
-
max 1.4.3.
- Status
-
vulnerable
WP Super Cache # fcad24bc-876e-4452-bca4-a072f8e86a02
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Super Cache [wp-super-cache] < 1.4.9 WP Super Cache < 1.4.9 - Cross-Site Scripting (XSS) The WP Super Cache WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected versions
-
max 1.4.9.
- Status
-
vulnerable
Dec 20, 2024
WP Super Cache # PSC-2024-64536
- PSC, Research URL
- Home page URL
- Application
- Date
- Aug 05, 2025
- Research Description
- WP Super Cache is an essential WordPress plugin designed to optimize website performance by generating static HTML files from dynamic content. These static files are served to visitors, significantly reducing server load and enhancing website speed. With its robust caching methods, including mod_rewrite, PHP caching, and WP-Cache, WP Super Cache ensures seamless performance for both logged-in and anonymous users. Following a rigorous security evaluation, WP Super Cache has successfully obtained the Plugin Security Certification (PSC) with the status PSC-2024-64536 from CleanTalk, affirming its commitment to delivering a secure and efficient solution.
- Affected versions
-
Min 3.1.3, max 3.1.3.
- Status
-
SAFE & CERTIFIED
Jun 06, 2024
WP Super Cache # CVE-2021-24209
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 06, 2021
- Research Description
- The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.
- Affected versions
-
max 1.7.2.
- Status
-
vulnerable
WP Super Cache # CVE-2013-2009
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 07, 2020
- Research Description
- WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution
- Affected versions
-
max 1.3.2.
- Status
-
vulnerable
WP Super Cache # CVE-2013-2011
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 27, 2019
- Research Description
- WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.
- Affected versions
-
max 1.3.2.
- Status
-
vulnerable
WP Super Cache # CVE-2021-24329
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 01, 2021
- Research Description
- The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.
- Affected versions
-
max 1.7.3.
- Status
-
vulnerable
WP Super Cache # CVE-2021-24312
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 01, 2021
- Research Description
- The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209.
- Affected versions
-
max 1.7.3.
- Status
-
vulnerable
WP Super Cache # CVE-2013-2008
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 07, 2020
- Research Description
- WordPress Super Cache Plugin 1.3 has XSS.
- Affected versions
-
max 1.3.1.
- Status
-
vulnerable