W3 Total Cache <= 0.9.4 - Cross-Site Request Forgery

2014-12-10 00:00
Mazin Ahmed

Strategic Overview

Status
Patched in 0.9.4.1
Affected PluginW3 Total Cache
Affected Version<= 0.9.4
CVSS4.3Medium
CVECVE-2014-9414
View all W3 Total Cache vulnerabilities

Vulnerability Overview

The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parameter and an empty _wpnonce parameter in the w3tc_mobile page to wp-admin/admin.php.

Technical Analysis

REMEDIATION: Update to version 0.9.4.1, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C