The Rapid Cache plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 1.2.3. This is due to plugin storing HTTP headers in the cached data. This makes it possible for unauthenticated attackers to poison the cache with custom HTTP headers that may be unsanitized which can lead to Cross-Site Scripting.
History

Mon, 24 Feb 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Megaoptim
Megaoptim rapid Cache
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:megaoptim:rapid_cache:*:*:*:*:*:wordpress:*:*
Vendors & Products Megaoptim
Megaoptim rapid Cache

Tue, 18 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Feb 2025 04:30:00 +0000

Type Values Removed Values Added
Description The Rapid Cache plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 1.2.3. This is due to plugin storing HTTP headers in the cached data. This makes it possible for unauthenticated attackers to poison the cache with custom HTTP headers that may be unsanitized which can lead to Cross-Site Scripting.
Title Rapid Cache <= 1.2.3 - Unauthenticated Cache Poisoning
Weaknesses CWE-524
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-02-18T17:07:04.172Z

Reserved: 2024-12-06T15:59:17.996Z

Link: CVE-2024-12314

cve-icon Vulnrichment

Updated: 2025-02-18T14:25:54.343Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-18T05:15:09.987

Modified: 2025-02-24T12:40:54.730

Link: CVE-2024-12314

cve-icon Redhat

No data.