cleantalk
Vulnerabilities and Security Researches

W3 Total Cache, 8bbc76fa6332bab2da8c13b6c3951743717967b8

Application

W3 Total Cache

Published on
Sep 26, 2016
Research Description
W3 Total Cache [w3-total-cache] < 0.9.5 W3 Total Cache <= 0.9.4.1 - Arbitrary File Upload The W3 Total Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 0.9.4.1. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Affected versions
max 0.9.5.
Status
vulnerable