W3 Total Cache Plugin for Wordpress contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is triggered when handling a direct request for the cache file and may disclose potentially sensitive password hash information to a remote attacker.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Uncoordinated Disclosure
OSVDB:
Vuln Dependent
Solution
OSVDB is not currently aware of a solution for this vulnerability. However the vendor has stated there will be a fix released 'soon'.