Description
WordPress plugin W3 Total Cache has a security issue that can occur if using database caching to disk. When database caching to disk with a web server with directory listing or web accessible wp-content/w3tc/dbcache/* directories an attacker can predict the names of cache files and retrieve their contents.
Remediation
Upgrade to W3 Total Cache version 0.9.2.5 or later.
References
Related Vulnerabilities
WordPress Other Vulnerability (CVE-2006-6808)
WordPress Plugin Better WordPress Minify Arbitrary File Disclosure (1.2.2)
Ruby Improper Authentication Vulnerability (CVE-2008-3905)
WordPress Improper Input Validation Vulnerability (CVE-2017-6815)
Zenphoto Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5595)