CVE-2022-31090
W3 Total Cache versions before 2.2.3 contain a vulnerability stemming from a dependency on an affected version of Guzzle that fails to properly strip Authorization headers when following HTTP redirects to different origins. When a request includes authentication credentials via the Curl handler and receives a redirect response to a URI with a different host, scheme, or port, the Authorization header may be forwarded to the new destination, exposing sensitive authentication information. Users should upgrade to version 2.2.3 or later to address this issue.
Based on public CVE data (MITRE/NVD).