Executive brief
WoltLab Suite Core is a popular community platform used to power forums and content sites. An authenticated attacker with low-level user privileges can exploit improper cache file handling to inject and execute arbitrary PHP code on the server, potentially compromising the entire site and user data.
Technical details
The vulnerability exists in WoltLab Suite Core's cache file generation mechanism, which uses predictable boundaries in nowdoc syntax. An authenticated user can inject attacker-controlled data that terminates the nowdoc prematurely, allowing arbitrary PHP code injection into executable cache files. This requires authentication but only low-privileged user access (no admin rights needed). The vulnerability affects WCF versions 6.1.0 through 6.1.22 and 6.2.0 through 6.2.5. Patches are available in versions 6.1.23 and 6.2.6, which implement unique boundaries for cache file generation.
Affected products
- WoltLab WCF 6.1.0 through 6.1.22, 6.2.0 through 6.2.5
Timeline
- 2026-09-11: disclosed
- 2026-07-30: patched: WCF 6.1.23 and 6.2.6 released with fix