CVE-2013-2010
CVE-2013-2010 is a critical-severity vulnerability in Automattic Wp Super Cache with a CVSS 3.x base score of 9.8. Its EPSS exploit-prediction score of 74% places it in the 99th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-74.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v2: 7.5
- EPSS exploit prediction: 74% (99th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-74
- Affected product: Automattic Wp Super Cache
- Published:
- Last modified:
Description
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
Frequently asked questions
- What is CVE-2013-2010?
- WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
- How severe is CVE-2013-2010?
- CVE-2013-2010 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2013-2010 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 74% (99th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2013-2010?
- CVE-2013-2010 primarily affects Automattic Wp Super Cache. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2013-2010?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2013-2010 published?
- CVE-2013-2010 was published on 2020-02-12 and last updated on 2026-06-16.
References
- http://packetstormsecurity.com/files/130999/WordPress-W3-Total-Cache-PHP-Code-Execution.html
- http://www.exploit-db.com/exploits/25137
- http://www.openwall.com/lists/oss-security/2013/04/24/9
- http://www.securityfocus.com/bid/59316
Affected products (2)
- cpe:2.3:a:automattic:wp_super_cache:*:*:*:*:*:wordpress:*:*
- cpe:2.3:a:boldgrid:w3_total_cache:*:*:*:*:*:wordpress:*:*
More vulnerabilities in Automattic Wp Super Cache
- CVE-2013-2009 — High (CVSS 8.8): WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution
- CVE-2021-24312 — High (CVSS 7.2): The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time,…
- CVE-2021-24209 — High (CVSS 7.2): The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due…
- CVE-2013-2008 — Medium (CVSS 6.1): WordPress Super Cache Plugin 1.3 has XSS.
- CVE-2021-24329 — Medium (CVSS 5.4): The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its…
All CVEs affecting Automattic Wp Super Cache →
Other CWE-74 (Improper Neutralization of Special Elements (Injection)) vulnerabilities
- CVE-2026-94097 — Critical (CVSS 10.0): A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file…
- CVE-2026-20130 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine…
- CVE-2026-82971 — Critical (CVSS 10.0): A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file…
- CVE-2026-54159 — Critical (CVSS 10.0): PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the…
- CVE-2026-44182 — Critical (CVSS 10.0): Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark,…
- CVE-2026-25586 — Critical (CVSS 10.0): SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty…
Browse all CWE-74 (Improper Neutralization of Special Elements (Injection)) vulnerabilities →