Description
WordPress Plugin W3 Total Cache is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process. WordPress Plugin W3 Total Cache version 0.9.2.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.9.2.9 or latest
References
https://wordpress.org/support/topic/pwn3d
http://blog.futtta.be/2013/04/18/wp-caching-plugin-vulnerability-debrief/
http://packetstormsecurity.com/files/121454/Wordpress-W3-Total-Cache-PHP-Code-Execution.html
Related Vulnerabilities
WordPress Plugin AVH Extended Categories Widgets Unspecified Vulnerability (4.0.2)
TYPO3 Inadequate Encryption Strength Vulnerability (CVE-2010-3670)
WordPress Plugin WP-Forum Multiple SQL Injection Vulnerabilities (1.7.8)
Drupal Core 9.1.x Cross-Site Scripting (9.1.0 - 9.1.13)
Apache Tomcat Uncontrolled Resource Consumption Vulnerability (CVE-2019-0199)