CVE-2021-24312: WP Super Cache < 1.7.3 - Authenticated Remote Code Execution
The parameters $cachepath, $wpcachedebugip, $wpsupercachefrontpagetext, $cachescheduledtime, $cacheddirectpages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-24312.
What is the severity of CVE-2021-24312?
The severity of CVE-2021-24312 is high with a CVSS score of 7.2.
Which software is affected by CVE-2021-24312?
The WP Super Cache WordPress plugin before 1.7.3 is affected by CVE-2021-24312.
What is the risk of CVE-2021-24312?
CVE-2021-24312 allows remote code execution (RCE), which can result in unauthorized access and control of the affected WordPress websites.
How can I fix CVE-2021-24312?
To fix CVE-2021-24312, update WP Super Cache plugin to version 1.7.3 or later, which includes a complete fix for the vulnerability.