4.3
CVSSv2

CVE-2014-8724

Published: 19/12/2014 Updated: 26/05/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 385
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin prior to 0.9.4.1 for WordPress, when debug mode is enabled, allows remote malicious users to inject arbitrary web script or HTML via the "Cache key" in the HTML-Comments, as demonstrated by the PATH_INFO to the default URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

boldgrid w3 total cache

Exploits

W3 Total Cache version 094 suffers from a cross site scripting vulnerability ...