Description
WordPress Plugin WP Super Cache is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process. WordPress Plugin WP Super Cache version 1.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.2 or latest
References
https://wordpress.org/support/topic/pwn3d
http://blog.futtta.be/2013/04/18/wp-caching-plugin-vulnerability-debrief/
Related Vulnerabilities
ReviveAdserver Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-7371)
Drupal Core 9.1.x Cross-Site Scripting (9.1.0 - 9.1.6)
WordPress Improper Input Validation Vulnerability (CVE-2008-5695)
CubeCart Session Fixation Vulnerability (CVE-2021-33394)
WordPress Plugin MapSVG Lite Cross-Site Request Forgery (4.2.4)