CVE-2014-9414
W3 Total Cache <= 0.9.4 - Cross-Site Request Forgery
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parameter and an empty _wpnonce parameter in the w3tc_mobile page to wp-admin/admin.php.
El plugin W3 Total Cache anterior a 0.9.4.1 de WordPress no maneja adecuadamente nonces vacíos, lo que permite a atacantes remotos dirigir ataques CSRF y secuestrar la autenticación de administradores para solicitudes de sitio móvil redirigen la URI a través del parámetro mobile_groups[*][redirect] y un parámetro vacío _wpnonce en la página w3tc_mobile a wp-admin/admin.php.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-12-10 CVE Published
- 2014-12-24 CVE Reserved
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2024-12-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/61562 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/534250/100/0/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/99352 | Vdb Entry | |
https://github.com/wp-plugins/w3-total-cache/commit/9a1cc9f70558282e135eb3120d271448c75b28dd#diff-86a10b31ab115483fe8111bedac14d15 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wordpress.org/plugins/w3-total-cache/changelog | 2023-05-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Boldgrid Search vendor "Boldgrid" | W3 Total Cache Search vendor "Boldgrid" for product "W3 Total Cache" | <= 0.9.4 Search vendor "Boldgrid" for product "W3 Total Cache" and version " <= 0.9.4" | wordpress |
Affected
|