CVE-2014-8724: XSS
Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the "Cache key" in the HTML-Comments, as demonstrated by the PATHINFO to the default URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8724?
CVE-2014-8724 is classified as a medium severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2014-8724?
To fix CVE-2014-8724, upgrade the W3 Total Cache plugin to version 0.9.4.1 or later.
Who is affected by CVE-2014-8724?
CVE-2014-8724 affects users of the W3 Total Cache plugin for WordPress with versions prior to 0.9.4.1.
What type of vulnerability is CVE-2014-8724?
CVE-2014-8724 is a Cross-site Scripting (XSS) vulnerability that allows attackers to inject arbitrary scripts.
When does CVE-2014-8724 occur?
CVE-2014-8724 occurs when debug mode is enabled in the W3 Total Cache plugin, allowing exploitation through the 'Cache key' in HTML comments.