CVE · High

CVE-2022-31090 — W3 Total Cache [w3-total-cache] < 2.2.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-31090 W3 Total Cache [w3-total-cache] < 2.2.3 Exposure of Sensitive Information to an Unauthorized Actor High 7.7 < 2.2.3 2.2.3 2022-06-20

CVE-2022-31090

W3 Total Cache versions before 2.2.3 contain a vulnerability stemming from a dependency on an affected version of Guzzle that fails to properly strip Authorization headers when following HTTP redirects to different origins. When a request includes authentication credentials via the Curl handler and receives a redirect response to a URI with a different host, scheme, or port, the Authorization header may be forwarded to the new destination, exposing sensitive authentication information. Users should upgrade to version 2.2.3 or later to address this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.