Plugin Vulnerability Hub
Plugin 12 known issues Latest disclosed Oct 03, 2022

WP Super Cache Vulnerabilities

Review known vulnerability records for the WordPress plugin WP Super Cache (`wp-super-cache`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2021-24312 and CVE-2021-24329, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
12
High or Critical
6
Patch Coverage
100%
Last Updated
Jan 22, 2024
Priority CVE Quick Links

Fast paths into WP Super Cache CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
6
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for WP Super Cache so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
12 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 5 high severity findings.
Recent CVEs
CVE-2021-24312 and CVE-2021-24329
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for WP Super Cache

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes
WP Super Cache <= 1.8 - Unauthenticated Cache Poisoning

The WP Super Cache plugin for WordPress is vulnerable to Unauthenticated Cache Poisoning in versions up to, and including, 1.8. This is due to insufficient parsing of URLs containing double slashes. This makes it possible for unauthenticated attackers to poison the site's cache p...

Published
Oct 03, 2022
Patched Release
1.9
Affected Versions
Versions up to 1.8
Next Step
Update to 1.9 or newer if supported.
Plugin High Patched: Yes CVE-2021-24312
CVE-2021-24312: WP Super Cache <= 1.7.2 - Authenticated Remote Code Execution

The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete f...

Published
May 14, 2021
Patched Release
1.7.3
Affected Versions
Versions before 1.7.3
Next Step
Update to 1.7.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-24329
CVE-2021-24329: WP Super Cache <= 1.7.2 - Authenticated (Admin+) Stored Cross-Site Scripting

The Twitter Bootstrap Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_cache_location' parameter in versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...

Published
Apr 12, 2021
Patched Release
1.7.3
Affected Versions
Versions before 1.7.3
Next Step
Update to 1.7.3 or newer if supported.
Plugin High Patched: Yes CVE-2021-24209
CVE-2021-24209: WP Super Cache <= 1.7.1 - Authenticated (Admin+) Remote Code Execution

The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is...

Published
Mar 16, 2021
Patched Release
1.7.2
Affected Versions
Versions before 1.7.2
Next Step
Update to 1.7.2 or newer if supported.
Plugin Medium Patched: Yes
WP Super Cache <= 1.4.8 - Cross-Site Scripting

The WP Super Cashe plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browse...

Published
Feb 03, 2017
Patched Release
1.4.9
Affected Versions
Versions up to 1.4.8
Next Step
Update to 1.4.9 or newer if supported.
Plugin Medium Patched: Yes
WP Super Cache <= 1.4.4 - Authenticated File Deletion

The WP Super Cache plugin for WordPress is vulnerable to Authenticated File Deletion in versions up to, and including, 1.4.4. Code that sanitized directory paths when deleting cache files wasn't secure and might allow an attacker to view or delete files named index.html. This mak...

Published
Sep 25, 2015
Patched Release
1.4.5
Affected Versions
Versions before 1.4.5
Next Step
Update to 1.4.5 or newer if supported.
Plugin High Patched: Yes
WP Super Cache <= 1.4.4 - PHP Object Injection

The WP Super Cache plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.4 via deserialization of untrusted input. This allows attackers to inject a PHP Object into cache files. If the cache file is accessed, it could allow the attacker...

Published
Sep 25, 2015
Patched Release
1.4.5
Affected Versions
Versions before 1.4.5
Next Step
Update to 1.4.5 or newer if supported.
Plugin Medium Patched: Yes
WP Super Cache <= 1.4.4 - Directory Listing

The WP Super Cache plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 1.4.4. This allows unauthenticated attackers to read the contents of arbitrary directories on the server, which can contain sensitive information.

Published
Sep 25, 2015
Patched Release
1.4.5
Affected Versions
Versions before 1.4.5
Next Step
Update to 1.4.5 or newer if supported.
Plugin High Patched: Yes
WP Super Cache < 1.4.3 - Cross Site Scripting

The WP Super Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$details[ ‘key’ ]` value in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web...

Published
Apr 07, 2015
Patched Release
1.4.3
Affected Versions
Versions before 1.4.3
Next Step
Update to 1.4.3 or newer if supported.
Plugin Critical Patched: Yes CVE-2013-2011
CVE-2013-2011: WP Super Cache < 1.3.2 - Remote Code Execution

WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.

Published
Aug 01, 2014
Patched Release
1.3.2
Affected Versions
Versions before 1.3.2
Next Step
Update to 1.3.2 or newer if supported.
Plugin High Patched: Yes CVE-2013-2009
CVE-2013-2009: WP Super Cache <= 1.2 - Remote Code Execution

The WP Super Cache plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.2. This allows unauthenticated attackers to execute code on the server.

Published
Aug 01, 2014
Patched Release
1.3
Affected Versions
Versions up to 1.2
Next Step
Update to 1.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2013-2008
CVE-2013-2008: WP Super Cache Plugin <= 1.3 - Multiple Cross-Site Scripting

The WordPress Super Cache Plugin 1.3 has XSS via several vulnerable parameters.

Published
Aug 01, 2014
Patched Release
1.3.1
Affected Versions
Versions up to 1.3
Next Step
Update to 1.3.1 or newer if supported.