WP Super Cache <= 1.4.4 - Directory Listing

2015-09-25 00:00
Anonymous

Strategic Overview

Status
Patched in 1.4.5
Affected PluginWP Super Cache
Affected Version< 1.4.5
CVSS5.3Medium
CVEN/A
View all WP Super Cache vulnerabilities

Vulnerability Overview

The WP Super Cache plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 1.4.4. This allows unauthenticated attackers to read the contents of arbitrary directories on the server, which can contain sensitive information.

Technical Analysis

REMEDIATION: Update to version 1.4.5, or a newer patched version --- IDENTIFIER: CWE-548 (Exposure of Information Through Directory Listing) The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C