Sceawere

Vulnerability Detail

CVE-2026-39767UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WPBase Cache Subscriber DoS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
16h ago
Vendor
baseapp
Product
WPBase Cache
Attack Type
CWE-770 Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-06T09:17:48.763Z",
  "pubdate": "2026-10-06T09:17:48.763Z",
  "executiveSummary": "The WPBase Cache plugin, specifically versions 5.5.6 and below, is susceptible to a Denial of Service (DoS) vulnerability triggered by authenticated users with subscriber-level access.\nThis vulnerability stems from improper input validation or resource management within the plugin's caching mechanism.\nBy leveraging this flaw, an authenticated subscriber can perform actions that force the exhaustion of server resources, such as memory or disk I/O, effectively rendering the website unavailable to legitimate users.\nThe risk implication is significant as it allows low-privileged attackers to disrupt service availability without requiring administrative oversight.\nExploitation requires active authentication on the target WordPress instance, but does not necessitate elevated privileges beyond the basic subscriber role.\nThis vulnerability highlights a critical lack of rate limiting or resource quotas for cache-clearing or cache-generation operations accessible to non-administrative users.",
  "technicalDetails": "The vulnerability resides in the core cache-handling logic of the WPBase Cache plugin, which fails to restrict access to resource-intensive operations to users with administrative capabilities.\nThe root cause is an insecure implementation of functional logic that allows subscribers to trigger cache-flushing, cache-invalidation, or mass-regeneration routines that are typically reserved for privileged administrative tasks.\nThe attack flow begins with an authenticated subscriber sending specifically crafted HTTP requests to the WordPress backend, targeting endpoints responsible for plugin cache management.\nBecause the plugin does not implement sufficient capability checks (such as current_user_can('manage_options')) on these endpoints, the server processes these requests as legitimate administrative operations.\nUpon receiving the malicious request, the vulnerable component initiates a synchronous operation that can be invoked repeatedly in quick succession.\nIf the attacker scripts these requests, they can induce a 'resource exhaustion' state by forcing the application to constantly overwrite or purge large portions of the cache directory.\nThis excessive I/O operation consumes significant CPU cycles and disk bandwidth. Given that WordPress cache mechanisms often involve serializing and writing large amounts of data, the continuous triggering of these functions leads to high system load averages, potentially hitting max_execution_time limits or causing database connection timeouts due to backend locking.\nFurthermore, if the cache regeneration logic includes external requests or complex database queries, the subscriber-triggered DoS effectively propagates to the underlying database and external service dependencies.\nThe payload does not require complex binary injection or code execution; it relies on the abuse of existing plugin functionality (Function-level Access Control vulnerability) to perform a resource-heavy action.\nThe impact is a degradation or total denial of service, where the server becomes unable to respond to incoming traffic due to the ongoing stress induced by the abused cache functionality.\nPost-exploitation, the attacker does not gain further access but has successfully achieved the objective of disabling the site's utility through service disruption."
}
CVE-2026-39767: WPBase Cache Subscriber DoS (MEDIUM Severity, CVSS: 6.5) | Sceawere