The W3 Total Cache plugin before 0.9.4.1 for WordPress does...
Vulnerability Description
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parameter and an empty _wpnonce parameter in the w3tc_mobile page to wp-admin/admin.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-9414
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/wp-plugins/w3-total-cache/commit/9a1cc9f70558282e135eb3120d271448c75b28dd#diff-86a10b31ab115483fe8111bedac14d15
- http://mazinahmed1.blogspot.com/2014/12/w3-total-caches-w3totalfail.html
- https://wordpress.org/plugins/w3-total-cache/changelog/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99352
- http://www.securityfocus.com/archive/1/534250/100/0/threaded
- http://seclists.org/fulldisclosure/2014/Dec/67
- http://packetstormsecurity.com/files/129512/W3-Total-Cache-0.9.4-Cross-Site-Request-Forgery.html
- http://secunia.com/advisories/61562
More from boldgrid
View All →Affected Vendor
boldgrid
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.