CVE-2019-6715 describes an arbitrary file read vulnerability in the W3 Total Cache plugin for WordPress, affecting versions prior to 0.9.4. An unauthenticated attacker can exploit this by manipulating the SubscribeURL field within SubscriptionConfirmation JSON data sent to pub/sns.php. This vulnerability carries a high severity CVSS score of 7.5, indicating a critical risk due to its network-based attack vector, low attack complexity, and potential for complete confidentiality compromise. While not listed on CISA's KEV catalog, its high EPSS score and the existence of Nuclei templates suggest a significant likelihood of exploitation, further evidenced by media coverage detailing its use against a high-profile target.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.4CPE matchmatch criteria | cpe:2.3:a:boldgrid:w3_total_cache:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.