Back to search
CVE-2021-24209
Published: Apr 5, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.
| Vendor | Product | Versions |
|---|---|---|
Unknown | WP Super Cache | affected 0 - < 1.7.2 |
References
https://wpscan.com/vulnerability/733d8a02-0d44-4b78-bbb2-37e447acd2f3
exploit
vdb-entry
technical-description
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now