WP Super Cache < 1.7.3 - Authenticated Remote Code Execution
Vulnerability Description
The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-24312
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- NGA
More from Automattic
View All →Affected Vendor
Automattic
View all reports →