Description
Two very popular WordPress caching plugins (WP Super Cache and W3 Total Cache) are vulnerable to PHP code execution via interpretation of dynamic snippets, that are contained inside a number of specific HTML-comment tags. WP Super Cache (before version 1.3) and W3 Total Cache (before version 0.9.2.9) are vulnerable to this issue.
Remediation
Upgrade the vulnerable plugin(s) to the latest version.
References
Related Vulnerabilities
Django CVE-2024-41989 Vulnerability (CVE-2024-41989)
Oracle HTTP Server Other Vulnerability (CVE-2002-0659)
Python Out-of-bounds Write Vulnerability (CVE-2019-12900)
MySQL CVE-2021-2042 Vulnerability (CVE-2021-2042)
Ruby on Rails Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-5419)