CVE-2014-9414: CSRF
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobilegroups[][redirect] parameter and an empty wpnonce parameter in the w3tcmobile page to wp-admin/admin.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9414?
CVE-2014-9414 has a medium severity level due to its potential for CSRF attacks against administrator authentication.
How do I fix CVE-2014-9414?
To fix CVE-2014-9414, upgrade the W3 Total Cache plugin to version 0.9.4.1 or later.
What type of vulnerability is CVE-2014-9414?
CVE-2014-9414 is a cross-site request forgery (CSRF) vulnerability.
Who is affected by CVE-2014-9414?
CVE-2014-9414 affects users of the W3 Total Cache plugin for WordPress versions prior to 0.9.4.1.
What could an attacker achieve by exploiting CVE-2014-9414?
An attacker exploiting CVE-2014-9414 could hijack the authentication of WordPress administrators to change the mobile site redirect URI.