1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

If you use W3 Total Cache or WP Super Cache... UPDATE NOW. You're open to exploit.

Discussion in 'Black Hat SEO' started by deviatus, Apr 27, 2013.

  1. deviatus

    deviatus Power Member

    Joined:
    May 25, 2007
    Messages:
    517
    Likes Received:
    387
    From my hosting company:

    We wanted to take this time to pass along information regarding serious security vulnerabilities recently discovered in two very popular WordPress plugins. They are:

    - WP Super Cache
    - W3 Total Cache

    These plugins have been reported as having a security hole that allows a hacker to control your WordPress installation by using a method called Remote Code Execution, which in this case is fairly simple to exploit. The good news is that the developers of both plugins have released a security update, disabling the vulnerable functions.

    Customers that are running WordPress, with WP Super Cache or W3 Total Cache installed, should immediately log in to their WordPress administration panel and upgrade the plugins as soon as possible in order to prevent the vulnerability from being exploited. Please note that if you have the plugins installed but they are not activated, it is still imperative that you update them, or delete them entirely.
     
    • Thanks Thanks x 1
    Last edited: Apr 27, 2013
  2. abhi007

    abhi007 Jr. VIP Jr. VIP

    Joined:
    Aug 31, 2010
    Messages:
    5,299
    Likes Received:
    3,740
    Location:
    snip.li/TubH
    so if updated then no danger ryt?
     
  3. Untouchable

    Untouchable Supreme Member

    Joined:
    Mar 22, 2012
    Messages:
    1,345
    Likes Received:
    1,173
    Location:
    Canada
    Update was released long back.
    Some people dont update. if you have WP you should update often.
     
  4. deviatus

    deviatus Power Member

    Joined:
    May 25, 2007
    Messages:
    517
    Likes Received:
    387
    Yes, just has to be their recent update.
     
  5. deviatus

    deviatus Power Member

    Joined:
    May 25, 2007
    Messages:
    517
    Likes Received:
    387
    Super Cache was just updated 4 days ago, don't know about W3.
     
  6. Untouchable

    Untouchable Supreme Member

    Joined:
    Mar 22, 2012
    Messages:
    1,345
    Likes Received:
    1,173
    Location:
    Canada
    W3 was updated long back. Its probably super cache that got delayed in the update.
     
  7. deviatus

    deviatus Power Member

    Joined:
    May 25, 2007
    Messages:
    517
    Likes Received:
    387
    Just checked, 11 days with W3.