PLUGIN SECURITY

Is Wp Super Cache safe?

A very fast caching engine for WordPress that produces static html files.

What this plugin does

  • Slug: wp-super-cache
  • Author: Automattic
  • 1000000+ active installs
  • 86/100 rating (1345 reviews on wordpress.org)
  • 64742819 all-time downloads
  • On WordPress.org since 2007-11-05

cachecachingperformanceWP CacheWP Super Cache

Maintenance status

  • Latest known version: 3.1.1
  • Last updated: 2026-05-27 5:38pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

6 known CVEs on file for Wp Super Cache. Reported between 2013 and 2022.

CVE Vulnerability Type Severity Affected Fixed in Published Status
WP Super Cache [wp-super-cache] < 1.9 Unknown < 1.9 1.9 2022-10-03 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.9 Unknown < 1.9 1.9 2022-10-03 ✓ fixed in latest
CVE-2021-24312 WP Super Cache [wp-super-cache] < 1.7.3 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') High 7.2 < 1.7.3 1.7.3 2021-05-14 ✓ fixed in latest
CVE-2021-24329 WP Super Cache [wp-super-cache] < 1.7.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.7.3 1.7.3 2021-04-12 ✓ fixed in latest
CVE-2021-24209 WP Super Cache [wp-super-cache] < 1.7.2 Improper Control of Generation of Code ('Code Injection') High 7.2 < 1.7.2 1.7.2 2021-03-16 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.4.9 Unknown < 1.4.9 1.4.9 2017-02-03 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.4.5 Unknown < 1.4.5 1.4.5 2015-09-26 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.4.5 Unknown < 1.4.5 1.4.5 2015-09-26 ✓ fixed in latest
+ 18 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
WP Super Cache [wp-super-cache] < 1.4.5 Unknown < 1.4.5 1.4.5 2015-09-25 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.4.5 Unknown < 1.4.5 1.4.5 2015-09-25 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.4.5 Unknown < 1.4.5 1.4.5 2015-09-25 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.4.3 Unknown < 1.4.3 1.4.3 2015-05-15 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.3.1 Unknown < 1.3.1 1.3.1 2015-05-15 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.4.3 Unknown < 1.4.3 1.4.3 2015-04-07 ✓ fixed in latest
CVE-2013-2009 WP Super Cache [wp-super-cache] < 1.3.2 High 8.8 < 1.3.2 1.3.2 2014-08-01 ✓ fixed in latest
CVE-2013-2008 WP Super Cache [wp-super-cache] < 1.3.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.3.1 1.3.1 2014-08-01 ✓ fixed in latest
CVE-2013-2011, CVE-2013-2009 WP Super Cache [wp-super-cache] < 1.3.2 Improper Encoding or Escaping of Output High 8.8 < 1.3.2 1.3.2 2014-08-01 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.3 Unknown < 1.3 1.3 2013-04-24 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.9 Unknown < 1.9 1.9 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.4.9 Unknown < 1.4.9 1.4.9 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.4.5 Unknown < 1.4.5 1.4.5 ✓ fixed in latest
WP Super Cache [wp-super-cache] < 1.4.3 Unknown < 1.4.3 1.4.3 ✓ fixed in latest
WP Super Cache < 1.4.3 - Stored Cross-Site Scripting (XSS) Unknown < 1.4.3 1.4.3 ✓ fixed in latest
WP Super Cache < 1.4.9 - Cross-Site Scripting (XSS) Unknown < 1.4.9 1.4.9 ✓ fixed in latest
WP Super Cache < 1.4.5 - PHP Object Injection Unknown < 1.4.5 1.4.5 ✓ fixed in latest
WP Super Cache < 1.9 - Unauthenticated Cache Poisoning Unknown < 1.9 1.9 ✓ fixed in latest

How to fix it

Keep Wp Super Cache updated — 3.1.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.