• About Us
  • Contributors
  • Guides
  • Speaking Engagements
  • Write for The SEM Post
  • Submit a tip or contact us!
  • Newsletters

The SEM Post

Latest News About SEO, SEM, PPC & Search Engines

  • Google
  • SEO
  • Mobile
  • Local
  • Bing
  • Pay Per Click
  • Facebook
  • Twitter
  • State of the Industry
You are here: Home / SEO / WP Super Cache Latest Plugin With Major XSS Exploit, Requires Immediate Update

WP Super Cache Latest Plugin With Major XSS Exploit, Requires Immediate Update

April 8, 2015 at 3:14 am PST By Jennifer Slegg

  • Facebook
  • Twitter
  • Google+
  • Pinterest
  • LinkedIn
  • Email
  • WhatsApp
  • Evernote
  • SMS

wpsupercacheIt has been a few weeks since we have seen an exploit in a WordPress plugin popular in the SEO community, but a new one has been discovered and fixed, this time in a popular caching plugin with over 1 million active installs.

The plugin in question is WP Super Cache, “A very fast caching engine for WordPress that produces static html files.”  It appears to be the most popular cache plugin offered on WordPress.org, so the potential for the number of websites that aren’t on top of updating plugins is pretty high.

If you are using WP Super Cache, you should upgrade immediately and ensure you are running version 1.4.4, which was quietly updated several days ago.  If you allow automatic plugin updates, you should double check it was updated properly and if you do manual plugin updates, you should update this immediately.

WP Super Cache is one of the popular WordPress cache plugins designed to improve website performance, with one of the features being reducing site speed, which many webmasters have been utilizing even more recently due to the upcoming mobile signal change.  Ironically, it was also the plugin featured in an example for the article on Google now including dates in answer boxes published earlier this week.

Using this vulnerability, an attacker using a carefully crafted query could insert malicious scripts to the plugin’s cached file listing page. As this page requires a valid nonce in order to be displayed, a successful exploitation would require the site’s administrator to have a look at that particular section, manually.

When executed, the injected scripts could be used to perform a lot of other things like adding a new administrator account to the site, injecting backdoors by using WordPress theme edition tools, etc.

It doesn’t appear that this has been actively used to inject malicious code into any sites using the plugin, however now that it is publicized with a fix released, you can expect that hackers will begin to inject links, new admin users and malware.  So it is very important that webmasters update this plugin as soon as possible before an injection occurs.

The Securi Blog has the full technical details about this XSS exploit.

This is the latest in a string of plugins popular with the SEO community to have a discovered exploit patched.  Google Analytics by Yoast, WordPress SEO by Yoast, Shareaholic, RevSlider and Fancybox-for-Wordpress have all recently fixed exploits, so you should also double check you are running the latest versions of these plugins as well.  It is always good to update all plugins when updates are available, because while many assume new releases are merely feature improvements, they oftentimes include exploit fixes that aren’t announced.

  • Facebook
  • Twitter
  • Google+
  • Pinterest
  • LinkedIn
  • Email
  • WhatsApp
  • Evernote
  • SMS
The following two tabs change content below.
  • Bio
  • Latest Posts
My Twitter profileMy Facebook profileMy Google+ profileMy LinkedIn profile

Jennifer Slegg

Founder & Editor at The SEM Post
Jennifer Slegg is a longtime speaker and expert in search engine marketing, working in the industry for almost 20 years. When she isn't sitting at her desk writing and working, she can be found grabbing a latte at her local Starbucks or planning her next trip to Disneyland. She regularly speaks at Pubcon, SMX, State of Search, Brighton SEO and more, and has been presenting at conferences for over a decade.
My Twitter profileMy Facebook profileMy Google+ profileMy LinkedIn profile

Latest posts by Jennifer Slegg (see all)

  • 2022 Update for Google Quality Rater Guidelines – Big YMYL Updates - August 1, 2022
  • Google Quality Rater Guidelines: The Low Quality 2021 Update - October 19, 2021
  • Rethinking Affiliate Sites With Google’s Product Review Update - April 23, 2021
  • New Google Quality Rater Guidelines, Update Adds Emphasis on Needs Met - October 16, 2020
  • Google Updates Experiment Statistics for Quality Raters - October 6, 2020

Filed Under: SEO, Wordpress

Sign up for our newsletter


Comments

  1. tanvir hasan says

    June 26, 2015 at 2:04 am

    you should double check it was updated properly and if you do manual plugin updates, you should update this immediately.

Founder & Editor

Jennifer Slegg (2052)

Sign up for our daily news recap & weekly newsletter.


Follow us online

  • Facebook
  • Google+
  • Linkedin
  • Pinterest
  • Twitter

Latest News

2022 Update for Google Quality Rater Guidelines – Big YMYL Updates

We finally have the first Google Quality Rater Guidelines update of 2022, and like usual, it is … [Read More...]

Recent Posts

  • 2022 Update for Google Quality Rater Guidelines – Big YMYL Updates
  • Google Quality Rater Guidelines: The Low Quality 2021 Update
  • Rethinking Affiliate Sites With Google’s Product Review Update
  • New Google Quality Rater Guidelines, Update Adds Emphasis on Needs Met
  • Google Updates Experiment Statistics for Quality Raters
  • Analyzing “How Google Search Works” Changes from Google
  • Google Quality Rater Guidelines Update: New Introduction, Rater Bias & Political Affiliations
  • Google Updates Quality Rater Guidelines: Reputation for News Sites; Video Content Updates; Quality for Information Sites
  • Google Makes Major Changes to NoFollow, Adds Sponsored & UGC Tags
  • Google Updates Quality Rater Guidelines Targeting E-A-T, Page Quality & Interstitials

Categories

  • Affiliate Marketing
  • Amazon
  • Apple
  • Bing
  • Branding
  • Browsers
  • Chrome
  • Content Marketing
  • Design
  • Domains
  • DuckDuckGo
  • Email
  • Facebook
  • Firefox
  • Foursquare
  • Google
    • Analytics
    • Google RankBrain
    • Quality Rater's Guidelines
  • History of Search
  • Industry Spotlight
  • Instagram
  • Internet Explorer
  • Links
  • Local
  • Mobile
  • Native Advertising
  • Other Search Engines
  • Pay Per Click
  • Pinterest
  • Publishers
  • Security
  • SEO
  • Snapchat
  • Social Media
  • State of the Industry
  • The SEM Post
  • Tools
  • Twitter
  • Uncategorized
  • User Experience
  • Video Marketing
  • Week in Review
  • Whitepapers
  • Wordpress
  • Yahoo
  • Yelp
  • YouTube
December 2025
MTWTFSS
« Aug  
1234567
891011121314
15161718192021
22232425262728
293031 

Meta

  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org

Copyright © 2025 · News Pro Theme On Genesis Framework · WordPress · Log in