WP-Super-Cache - Critical Vulnerability, Be sure to upgrade

13
16
2.9K followers

As many as 1 million sites imperiled by dangerous bug in WordPress plugin

As many as a million websites could be imperiled by a critical vulnerability recently discovered in WP-Super-Cache, a WordPress plugin that generates static HTML files from dynamic WordPress blogs.

The persistent cross-site scripting bug allows attackers to insert malicious code into WordPress-published pages that use the extension, according to a blog post published Tuesday by security firm Sucuri. Anyone who relies on the plug in should immediately upgrade to version 1.4.4, which has fixes for that bug and several others.

<snip>

Full article: http://arstechnica.com/security/2015/04/as-many-as-1-million-sites-imperiled-by-dangerous-bug-in-wordpress-plugin

13
16

Join FREE & Launch Your Business!

Exclusive Bonus - Offer Ends at Midnight Today

00

Hours

:

00

Minutes

:

00

Seconds

2,000 AI Credits Worth $10 USD

Build a Logo + Website That Attracts Customers

400 Credits

Discover Hot Niches with AI Market Research

100 Credits

Create SEO Content That Ranks & Converts

800 Credits

Find Affiliate Offers Up to $500/Sale

10 Credits

Access a Community of 2.9M+ Members

By continuing, you agree to our Terms of Service and Privacy Policy
No credit card required

Recent Comments

16

Thanks for the heads up Bob! :)

Don't you mean version 4.1.1?

The 1.4.4 version is what's listed in the article. If the plugin is already at a 4.0 or 4.1 level, that must be a typo. Since I don't have that particular plugin installed, I'm just going by what the article said.

Thanks Bob. I think I was confusing it with another number.

That's totally understandable given the number of different plugins at various version numbers. :=) I just confirmed that the latest version is 1.4.4 as it's listed in the article. (I should have done that in response to your previous comment.)

Thanks for sharing

Thanks for sharing Bob. I've disabled the plugin on my websites because it interferes with my ability to see the changes I make (in real time). ~Marion

As long as you have the plugin disabled, I don't think that your sites are exposed to this vulnerabilty. (Not 100% certain on that.) You may want to update it anyway just in case you do want to reenable it in the future.

I am a bit surprised, though, that the plugin keeps you from seeing changes as you're making them in your admin area. I would have expected that the cache would be cleared whenever you update a post or page.

1

I should have written in the past tense. I haven't checked it recently because of previous problems.

Thank you for the warning! :)

Thanks Bob mine has been updated

Barry

Thanks Bob

Thank you Bob. What would we do without WA family like you. Blessings.....
Shirley

Thanks!

Thank you for the useful info Bob

See more comments

Join FREE & Launch Your Business!

Exclusive Bonus - Offer Ends at Midnight Today

00

Hours

:

00

Minutes

:

00

Seconds

2,000 AI Credits Worth $10 USD

Build a Logo + Website That Attracts Customers

400 Credits

Discover Hot Niches with AI Market Research

100 Credits

Create SEO Content That Ranks & Converts

800 Credits

Find Affiliate Offers Up to $500/Sale

10 Credits

Access a Community of 2.9M+ Members

By continuing, you agree to our Terms of Service and Privacy Policy
No credit card required

2.9M+

Members

190+

Countries Served

20+

Years Online

50K+

Success Stories

The world's most successful affiliate marketing training platform. Join 2.9M+ entrepreneurs building their online business with expert training, tools, and support.

© 2005-2025 Wealthy Affiliate
All rights reserved worldwide.

🔒 Trusted by Millions Worldwide

Since 2005, Wealthy Affiliate has been the go-to platform for entrepreneurs looking to build successful online businesses. With industry-leading security, 99.9% uptime, and a proven track record of success, you're in safe hands.