The Cache Purger
- <= 2.3.20
A vulnerability exists in The Cache Purger plugin for WordPress, affecting all versions up to and including 2.3.20. The issue stems from the plugin's failure to properly verify user authorization, allowing authenticated users with subscriber-level access and above to bypass authorization and delete log entries. This is achieved by exploiting the 'the_log_purge' parameter, which is accessible through a nonce that is inadvertently made available to all authenticated users via the admin bar.
Exploitation of this vulnerability allows for unauthorized deletion of log entries, specifically from the cache-purge audit log, which is located at wp-content/purge.log. This deletion is permanent and removes the entire audit history, potentially hindering the ability to track cache purge actions.
To reproduce this vulnerability, an authenticated user with subscriber-level access can navigate to a frontend page where the admin bar is visible. From there, the user can access the 'Purge the Log' option, which triggers the deletion of the purge log without proper authorization checks.
Users are advised to update the The Cache Purger plugin to version 2.3.21 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.