CVE-2023-5359
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Sep 25, 2024
Updated: Sep 30, 2024
CWE ID 312
CWE ID 200
Summary
CVE-2023-5359 is a vulnerability affecting the W3 Total Cache plugin for WordPress. In versions up to 2.7.5, sensitive information, specifically Google OAuth API secrets, are stored in plaintext within the plugin source. This issue poses a significant risk as it enables unauthenticated attackers to impersonate the W3 Total Cache plugin and gain access to user account information. This vulnerability does not impact the functionality or appearance of the affected WordPress site.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Boldgrid W3 Total Cache