
4/25/2013 · Matthew Prince
What this post added
Cloudflare automatically applied a network rule to protect all accounts against a remote code execution vulnerability in W3 Total Cache (versions 0.9.2.8 and below) and WP Super Cache (versions 1.2 and below). The vulnerability, discovered by Sucuri, allows attackers to execute arbitrary PHP code on a server by exploiting functions like mfunc, mclude, and dynamic-cached-content. The post emphasizes the importance of immediate plugin upgrades despite the network-level protection.