Vulnerability Details CVE-2014-9414
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parameter and an empty _wpnonce parameter in the w3tc_mobile page to wp-admin/admin.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.2%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2014-9414
-
cpe:2.3:a:boldgrid:w3_total_cache:-
-
cpe:2.3:a:boldgrid:w3_total_cache:0.5
-
cpe:2.3:a:boldgrid:w3_total_cache:0.6
-
cpe:2.3:a:boldgrid:w3_total_cache:0.7
-
cpe:2.3:a:boldgrid:w3_total_cache:0.7.5
-
cpe:2.3:a:boldgrid:w3_total_cache:0.7.5.1
-
cpe:2.3:a:boldgrid:w3_total_cache:0.7.5.2
-
cpe:2.3:a:boldgrid:w3_total_cache:0.8
-
cpe:2.3:a:boldgrid:w3_total_cache:0.8.5
-
cpe:2.3:a:boldgrid:w3_total_cache:0.8.5.1
-
cpe:2.3:a:boldgrid:w3_total_cache:0.8.5.2
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.0
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.1
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.1.1
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.1.2
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.1.3
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.2
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.2.1
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.2.2
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.2.3
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.2.4
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.2.5
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.2.6
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.2.7
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.2.8
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.3
-
cpe:2.3:a:boldgrid:w3_total_cache:0.9.4