Exploits / Vulnerability Discovered : 2021-03-29 |
Type : webapps |
Platform : php
This exploit / vulnerability Wordpress plugin wp super cache 1.7.1 remote code execution (authenticated) is for educational purposes only and if it is used you will do on your own risk!
[i] An Authenticated RCE vulnerability was discovered in the WP Super Cache plugin through 1.7.1 for WordPress.
[i] RCE due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.
[i] Another possible attack vector: from XSS to RCE.
### -- [ Impact: ]
[~] Full compromise of the vulnerable web application and also web server.