pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| W3_total_cache | Boldgrid | * | 0.9.4 (excluding) |