WordPress Plugin Vulnerabilities
W3 Total Cache < 0.9.7.4 - Blind SSRF and RCE via phar
Description
The implementation of `opcache_flush_file` calls `file_exists` with a parameter fully controlled by the user.
Proof of Concept
Affects Plugins
References
Miscellaneous
Original Researcher
Thomas Chauchefoin
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2019-05-06 (about 7 years ago)
Added
2019-05-06 (about 7 years ago)
Last Updated
2026-04-13 (about 1 month ago)