cleantalk
Vulnerabilities and Security Researches

WP Super Cache, 43bcb64c982f04582dc01eb288ff44b4cfc0bc39

Application

WP Super Cache

Published on
Sep 25, 2015
Research Description
WP Super Cache [wp-super-cache] < 1.4.5 WP Super Cache <= 1.4.4 - Authenticated File Deletion The WP Super Cache plugin for WordPress is vulnerable to Authenticated File Deletion in versions up to, and including, 1.4.4. Code that sanitized directory paths when deleting cache files wasn't secure and might allow an attacker to view or delete files named index.html. This makes it possible for authenticated attackers to delete some index files, which can lead to some site accessibility issues and information disclosure.
Affected versions
max 1.4.5.
Status
vulnerable