W3 Total Cache is vulnerable to Path Traversal
96
Critical Risk
The page cache key is built from the request path without rejecting traversal segments, so cache file paths can escape the intended cache directory. An unauthenticated attacker can write a file into any existing directory on the server, inside or outside the web root, and overwrite whatever occupies that name. On Apache this can overwrite .htaccess files, breaking the site and removing hardening rules. The fix validates the request path used when constructing cache file names.
You are affected if you are using a version that falls within the vulnerable range.
W3 Total Cache is vulnerable to Path Traversal in versions 0.0.1 - 2.10.4.
Upgrade the W3 Total Cache library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant