Description
pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.
Remediation
References
Related Vulnerabilities
WordPress Plugin Insert Pages Multiple Vulnerabilities (3.6.1)
Squid Incorrect Conversion between Numeric Types Vulnerability (CVE-2023-46848)
Grafana URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-29170)
WordPress Plugin YITH WooCommerce Product Add-Ons Cross-Site Scripting (2.2.2)