Looking for the vulnerability index of Invicti's legacy products?
WordPress Plugin W3 Total Cache PHP Code Injection (0.9.2.8) - Vulnerability Database

WordPress Plugin W3 Total Cache PHP Code Injection (0.9.2.8)

Description

WordPress Plugin W3 Total Cache is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process. WordPress Plugin W3 Total Cache version 0.9.2.8 is vulnerable; prior versions may also be affected.

Remediation

Update to plugin version 0.9.2.9 or latest

Related Vulnerabilities