ZeroHour

CVE-2019-6715

PoC ×2
CVSS 3.1
7.5 high
EPSS
19%p97
Published
()
Modified
Description

pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.

Vendors
boldgrid
Products
w3 total cache
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.