5
CVSSv2

CVE-2019-6715

Published: 01/04/2019 Updated: 26/05/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

pub/sns.php in the W3 Total Cache plugin prior to 0.9.4 for WordPress allows remote malicious users to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

boldgrid w3 total cache

Exploits

This Metasploit module exploits an unauthenticated directory traversal vulnerability in WordPress plugin W3 Total Cache version 0926 through 093, allowing arbitrary file read with the web server privileges ...

Github Repositories

cve-2019-6715 Shout out to TomNomNom for 999% of his code Build go get githubcom/fatih/color go build Usage cat listtxt | /2019-6715 All vuln urls are logged in textlog CVE 2019-6715 Description: pub/snsphp in the W3 Total Cache plugin before 094 for WordPress allows remote attackers to