Update: Popular WordPress Plugin Leaves Sensitive Data in the Open
ID: 56b92409-7e29-5a9a-8409-0ae4985f3308
STIX ID: report--56b92409-7e29-5a9a-8409-0ae4985f3308
Feed Name: Security Ledger
A security researcher discovered that the popular W3 Total Cache WordPress plugin, when installed with default or weak configuration, can leave cache directories and files publicly accessible and downloadable—exposing sensitive data such as password hashes. The researcher developed a proof-of-concept brute-force approach to retrieve predictable cache keys, identified multiple sites with exposed caches, and recommended disabling database/object caching and flushing caches while the vendor prepares a fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
