logo

A flaw in the W3 Total Cache plugin exposes hundreds of thousands of WordPress sites to attacks

ID: 6bc569eb-8100-5e54-bb90-863bddf56f2d

STIX ID: report--6bc569eb-8100-5e54-bb90-863bddf56f2d

Feed Name: Security Affairs

Threat Score
72/100

Date Published: 2025-01-19

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A high-severity vulnerability (CVE-2024-12365, CVSS 8.5) in the W3 Total Cache WordPress plugin (<= 2.8.1) allows authenticated Subscriber-level attackers to bypass authorization checks, retrieve the plugin nonce, trigger SSRF and disclose internal/cloud metadata; a patch (2.8.2) exists but many sites remain unpatched, putting a large number of WordPress installations at risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.