CVE-2024-12314
Rapid Cache <= 1.2.3 - Unauthenticated Cache Poisoning
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.2EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
18 Feb 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Rapid Cache plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 1.2.3. This is due to plugin storing HTTP headers in the cached data. This makes it possible for unauthenticated attackers to poison the cache with custom HTTP headers that may be unsanitized which can lead to Cross-Site Scripting.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Affected products
megaoptim · Rapid CacheWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →