WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in WP Super Cache

A very fast caching engine for WordPress that produces static html files.

12Reported vulnerabilities
9.8Highest CVSS score
3.1.1Latest version
1,000,000+Active installs

What to do now

Update WP Super Cache to 1.9 or later. 12 of these have a fixed version available. Updating resolves them.

Plugin last updated: May 27, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2013-2010 Critical 9.8 73.9% 1.2 and earlier
0.9.2.8 and earlier
0.9.2.9 February 12, 2020
CVE-2021-24209 High 7.2 27.7% Before 1.7.2 1.7.2 April 5, 2021
CVE-2013-2009 High 8.8 13.0% 1.2 to 1.2 (inclusive) 1.3 February 7, 2020
CVE-2021-24312 High 7.2 1.9% Before 1.7.3 1.7.3 June 1, 2021
CVE-2021-24329 Medium 5.4 4.5% Before 1.7.3 1.7.3 June 1, 2021
WF-634ccd08-4f2e-4a06-8c64-dfe38fa3a481 High 8.1 Before 1.4.5 1.4.5 September 25, 2015
WF-353804e8-0d5a-4633-974c-6eb7a3eeba61 High 7.2 Before 1.4.3 1.4.3 April 7, 2015
CVE-2013-2008 Medium 6.1 1.5% 1.3 to 1.3 (inclusive) 1.3.1 February 7, 2020
WF-505edcf7-7015-453e-abd2-e2cd68a3a9f6 Medium 6.5 1.8 and earlier 1.9 October 3, 2022
WF-51d98277-a1d7-4708-8daf-88948a235375 Medium 5.3 1.4.8 and earlier 1.4.9 February 3, 2017
WF-13981037-e698-42a7-9471-e27486cf1a4e Medium 5.3 Before 1.4.5 1.4.5 September 25, 2015
WF-51b6c73d-fd4f-4469-9859-fbae61b5924c Medium 5.4 Before 1.4.5 1.4.5 September 25, 2015

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.