WP Super Cache <= 1.4.4 - Directory Listing
2015-09-25 00:00
AnonymousStrategic Overview
Vulnerability Overview
The WP Super Cache plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 1.4.4. This allows unauthenticated attackers to read the contents of arbitrary directories on the server, which can contain sensitive information.
Technical Analysis
REMEDIATION: Update to version 1.4.5, or a newer patched version --- IDENTIFIER: CWE-548 (Exposure of Information Through Directory Listing) The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C