A flaw in the W3 Total Cache plugin exposes hundreds of thousands of WordPress sites to attacks
ID: 6bc569eb-8100-5e54-bb90-863bddf56f2d
STIX ID: report--6bc569eb-8100-5e54-bb90-863bddf56f2d
Feed Name: Security Affairs
Threat Score
A high-severity vulnerability (CVE-2024-12365, CVSS 8.5) in the W3 Total Cache WordPress plugin (<= 2.8.1) allows authenticated Subscriber-level attackers to bypass authorization checks, retrieve the plugin nonce, trigger SSRF and disclose internal/cloud metadata; a patch (2.8.2) exists but many sites remain unpatched, putting a large number of WordPress installations at risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
