High Risk XSS Vulnerability Discovered in W3 Total Cache Plugin
You might need to disable your plugin; please read:
REF:
https://secupress.me/w3-total-cache-vulnerable-xss-high-risk/
https://wptavern.com/high-risk-xss-vulnerability-discovered-in-w3-total-cache-plugin
Latest vulnerability is not fixed.
version 0.9.4.1
Compatible up to: 4.5.4
Last Updated: 6 months ago
Active Installs: 1+ million
W3 Total Cache was updated six months ago with a fix for two security issues. The last major update, 0.9.4, was released in 2014. After many users began to wonder if the plugin was abandoned, we spoke with author Frederick Townes in March to learn the status of W3 Total Cache. His said that development and other operations have been ongoing and that his team is working towards leaving officially beta and moving towards a 1.0 release. No major updates have been issued and Townes’ company blog has remained silent.
At this point, the only option users have is to disable the plugin or use an account with author or editor permissions instead of the administrator account. The plugin’s author has been contacted about the vulnerability but there is no security update available via WordPress.org yet.
Seems that on GitHub found a patch, but of course, no one will receive an push notification through WordPress.
LOL
Are you sure you that Frederick Townes not won the lottery 🙂 and right now is on a beach somewhere unknown?
Really Chris, they have capital needed and popularity so don’t tell me they don’t have staff to fix vulnerability every hour if they want.
I got no feeling for them one way or the other, I have some time that I stopped using cache plugins, pity for those who use it.
Don’t really fully understand your post, but whatever. I don’t use the plugin, but some here do. The comment I posted was from the article source, not my voice/opinion.
I have no dog in the hunt; and just sharing the info, since I stay on top of this stuff along with the latest openSSL vulnerabilities, etc. as we are a PCI-DSS certified system here. Most people here don’t stay on top of security hence so many “hacked” sites this year from TD theme users (unrelated to theme, of course).
Anybody using the plugin should look into the issues, if they care. 🙂
People get their sites hacked by not staying on top of this stuff; so shared in that spirit.
Do as you will.
Hey @Chris
I’m not speak English fluently so maybe for some words my Google friend translator played a bad turn, if anything I said sounds bad, sorry, really I have no intention.
Of course it is a very nice detail from your part to share such info. Although I do not use it but I have a lot of friends that if. What I said is that it seems strange that someone as well known and such good reputation & popularity leave in oblivion such project.
I use “pity” word (i think it is not right word for this proposition) in the previous reply, but my intention was to say that I feel sorry for those who use it.
Some time is very hard to explain in written words what you think.
