W3 Total Cache <= 0.9.4.1 - Authenticated Arbitrary File Download
2016-09-26 00:00
SecuPressStrategic Overview
Vulnerability Overview
The W3 Total Cache plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 0.9.4.1 This can allow an administrator attacker to extract sensitive data from wp-config.php that could be used to fully take over the site.
Technical Analysis
REMEDIATION: Update to version 0.9.5, or a newer patched version
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C