Re: [FD] XSS Wordpress W3 Total Cache <= 0.9.4.1

2016-09-27 Thread Simon Rawet
Hi Fernando, Do you have a timeline for this issue? Additionally do you have any contact details for the w3tc team you could share? All my attempts to contact them have fallen short. On 21/09/16 13:56, Fernando A. Lagos Berardi wrote: > [+] Description: Cross-Site Scripting vulnerability was fo

Re: [FD] XSS Wordpress W3 Total Cache <= 0.9.4.1

2016-09-27 Thread Fernando A. Lagos Berardi
Hi Simon, I have found this vulnerability 1 year ago (july 2015). I've tried to contact them many times but no answers. cheers, Fernando 2016-09-22 5:28 GMT-03:00 Simon Rawet : > Hi Fernando, > > Do you have a timeline for this issue? > > Additionally do you have any contact details for the w

[FD] XSS Wordpress W3 Total Cache <= 0.9.4.1

2016-09-21 Thread Fernando A. Lagos Berardi
[+] Description: Cross-Site Scripting vulnerability was found on Wordpress W3 Total Cache (w3tc) plugin. [+] Plugin Version tested: <= 0.9.4.1 (latest) [+] Wordpress version tested: 4.0.0 - 4.6.1 (latest) -- [+] Component: W3 Total Cache Admin (performance menu) -> Sup