Website Security & Threat Management
W3TC and WP Super Cache Vulnerability Discovered, We've Automatically Patched

W3TC and WP Super Cache Vulnerability Discovered, We've Automatically Patched

4/25/2013 · Matthew Prince

What this post added

Cloudflare automatically applied a network rule to protect all accounts against a remote code execution vulnerability in W3 Total Cache (versions 0.9.2.8 and below) and WP Super Cache (versions 1.2 and below). The vulnerability, discovered by Sucuri, allows attackers to execute arbitrary PHP code on a server by exploiting functions like mfunc, mclude, and dynamic-cached-content. The post emphasizes the importance of immediate plugin upgrades despite the network-level protection.

Read the original post ↗