The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account information in successful conditions. This would not impact the WordPress users site in any way.
History

Mon, 30 Sep 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Boldgrid
Boldgrid w3 Total Cache
Weaknesses CWE-312
CPEs cpe:2.3:a:boldgrid:w3_total_cache:*:*:*:*:*:wordpress:*:*
Vendors & Products Boldgrid
Boldgrid w3 Total Cache

Tue, 24 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 24 Sep 2024 07:45:00 +0000

Type Values Removed Values Added
Description The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account information in successful conditions. This would not impact the WordPress users site in any way.
Title W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-09-24T07:30:45.348Z

Updated: 2024-09-24T13:37:04.524Z

Reserved: 2023-10-03T13:24:45.256Z

Link: CVE-2023-5359

cve-icon Vulnrichment

Updated: 2024-09-24T13:36:59.913Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-25T01:15:39.730

Modified: 2024-09-30T14:19:15.970

Link: CVE-2023-5359

cve-icon Redhat

No data.