{"id":626,"date":"2013-04-26T13:07:43","date_gmt":"2013-04-26T13:07:43","guid":{"rendered":"http:\/\/reseller-hosting-themes.com\/wordpress\/?p=626"},"modified":"2013-04-26T13:09:14","modified_gmt":"2013-04-26T13:09:14","slug":"important-security-update-for-wp-super-cache-and-w3tc","status":"publish","type":"post","link":"https:\/\/reseller-hosting-themes.com\/wordpress\/important-security-update-for-wp-super-cache-and-w3tc\/","title":{"rendered":"Important Security Update for WP Super Cache and W3TC"},"content":{"rendered":"<p>Just a month ago, a very serious security issue was discovered with two of the most popular caching plugins for WordPress &#8211; <a href=\"https:\/\/wordpress.org\/extend\/plugins\/wp-super-cache\/\">WP Super Cache<\/a> and <a href=\"https:\/\/wordpress.org\/extend\/plugins\/w3-total-cache\/\">W3 Total Cache<\/a>. They allow users to execute custom code via the comment form of your blog. <\/p>\n<p>In order to test if your blog is vulnerable to the issue, you can simply paste the following code:<\/p>\n<pre>&lt;!\u2013mfunc echo PHP_VERSION; \u2013&gt;&lt;!\u2013\/mfunc\u2013&gt;<\/pre>\n<p>as a comment to any of your posts. If you don&#8217;t see anything, you are safe. However, if you see something in the lines of: <em>5.2.17<\/em>, then you are in trouble.<\/p>\n<p>Seeing <em>5.2.17<\/em> means that anyone can execute PHP code on your account, bypassing any logins and authentications. This basically means that someone can take over your WordPress website, or even your hosting account.<\/p>\n<p>Note: if you use a custom comments solution, like Disqus, then you are safe and you don&#8217;t have to worry.<\/p>\n<p>There are also updates for WP Super Cache and W3TC that address the issue. If you use them, you should go ahead and update as soon as possible.<\/p>\n<p>If you wish to change your caching plugin altogether, you can consider Quick Cache or Hyper Cache.<\/p>\n<p>This was first reported in the <a href=\"https:\/\/wordpress.org\/support\/topic\/pwn3d\">WordPress forums<\/a> over a month ago. Recently Tony Perez of Sucuri <a href=\"https:\/\/blog.sucuri.net\/2013\/04\/update-wp-super-cache-and-w3tc-immediately-remote-code-execution-vulnerability-disclosed.html\">blogged about the issue<\/a> in order to generate more awareness.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Important Security Update for WP Super Cache and W3 Total Cache was recently released. It fixes a major security hole in the WordPress comments system. Update as soon as possible in order to protect your WordPress website.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"_links":{"self":[{"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/posts\/626"}],"collection":[{"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/comments?post=626"}],"version-history":[{"count":11,"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/posts\/626\/revisions"}],"predecessor-version":[{"id":637,"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/posts\/626\/revisions\/637"}],"wp:attachment":[{"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/media?parent=626"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/categories?post=626"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/tags?post=626"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}