CVE

CVE-2014-9414 — W3 Total Cache [w3-total-cache] < 0.9.4.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2014-9414 W3 Total Cache [w3-total-cache] < 0.9.4.1 Cross-Site Request Forgery (CSRF) Unknown < 0.9.4.1 0.9.4.1 2014-09-08

CVE-2014-9414

W3 Total Cache versions prior to 0.9.4.1 fail to properly validate empty nonces, enabling attackers to execute cross-site request forgery attacks against administrators. An attacker could exploit this vulnerability by crafting a request with an empty nonce value to modify the mobile site redirect URI through the mobile_groups[*][redirect] parameter on the w3tc_mobile admin page, potentially hijacking administrator authentication and altering site configuration.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.