CVE-2014-9414
W3 Total Cache versions prior to 0.9.4.1 fail to properly validate empty nonces, enabling attackers to execute cross-site request forgery attacks against administrators. An attacker could exploit this vulnerability by crafting a request with an empty nonce value to modify the mobile site redirect URI through the mobile_groups[*][redirect] parameter on the w3tc_mobile admin page, potentially hijacking administrator authentication and altering site configuration.
Based on public CVE data (MITRE/NVD).