Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-5359


The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account information in successful conditions. This would not impact the WordPress users site in any way.


Published

2024-09-25T01:15:39.730

Last Modified

2024-09-30T14:19:15.970

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 3.7 (LOW)

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    CWE-312

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application boldgrid w3_total_cache < 2.7.6 Yes

References