CVE · High

CVE-2021-24312 — WP Super Cache [wp-super-cache] < 1.7.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24312 WP Super Cache [wp-super-cache] < 1.7.3 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') High 7.2 < 1.7.3 1.7.3 2021-05-14

CVE-2021-24312

WP Super Cache versions before 1.7.3 contain a remote code execution vulnerability in several configuration parameters including $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, and $cached_direct_pages, which fail to properly sanitize input containing dollar signs and newline characters. An attacker can exploit this flaw by accessing the wp-cache-config.php file directly and injecting malicious code that will be executed on the server. This issue represents an incomplete resolution of the previously documented CVE-2021-24209.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.