W3 Total Cache <= 0.9.4.1 - Authenticated Arbitrary File Download

2016-09-26 00:00
SecuPress

Strategic Overview

Status
Patched in 0.9.5
Affected PluginW3 Total Cache
Affected Version<= 0.9.4.1
CVSS4.9Medium
CVEN/A
View all W3 Total Cache vulnerabilities

Vulnerability Overview

The W3 Total Cache plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 0.9.4.1 This can allow an administrator attacker to extract sensitive data from wp-config.php that could be used to fully take over the site.

Technical Analysis

REMEDIATION: Update to version 0.9.5, or a newer patched version

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C