W3 Total Cache <= 0.9.4.1 - Weak validation of Amazon SNS push messages

2016-11-10 00:00
Anonymous

Strategic Overview

Status
Patched in 0.9.5
Affected PluginW3 Total Cache
Affected Version<= 0.9.4.1
CVSS7.2High
CVEN/A
View all W3 Total Cache vulnerabilities

Vulnerability Overview

The W3 Total Cache plugin for WordPress is vulnerable to weak validation of Amazon SNS push messages in versions up to, and including, 0.9.4.1. This makes it possible for attackers to perform a variety of actions concerning the server's cache, such as performing a Denial of Service attack on the site.

Technical Analysis

REMEDIATION: Update to version 0.9.5, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C