CVE-2013-2011: Automattic w3 Super Cache

High severity, CVSS 8.8. EPSS: 5.1% chance of exploitation in the next 30 days.

WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.

Affected products

  • Automattic w3 Super Cache: before 1.3.2 (fixed in 1.3.2)

Published 2019-12-26. Last modified 2026-06-16.