WP Super Cache <= 1.4.4 - Authenticated File Deletion

2015-09-25 00:00
Anonymous

Strategic Overview

Status
Patched in 1.4.5
Affected PluginWP Super Cache
Affected Version< 1.4.5
CVSS5.4Medium
CVEN/A
View all WP Super Cache vulnerabilities

Vulnerability Overview

The WP Super Cache plugin for WordPress is vulnerable to Authenticated File Deletion in versions up to, and including, 1.4.4. Code that sanitized directory paths when deleting cache files wasn't secure and might allow an attacker to view or delete files named index.html. This makes it possible for authenticated attackers to delete some index files, which can lead to some site accessibility issues and information disclosure.

Technical Analysis

REMEDIATION: Update to version 1.4.5, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C