W3 Total Cache plugin flaw exposes 1 million WordPress sites to attacks
ID: e24993a6-9b40-5f3f-8a31-106f7715795e
STIX ID: report--e24993a6-9b40-5f3f-8a31-106f7715795e
Feed Name: Bleeping Computer
A critical vulnerability (CVE-2024-12365) in the W3 Total Cache WordPress plugin—caused by a missing capability check in the is_w3tc_admin_page function—allows authenticated users with subscriber-level access to perform SSRF and access sensitive information (including cloud instance metadata), potentially enabling further attacks; the developer fixed the issue in version 2.8.2, but hundreds of thousands of sites remain unpatched, so site owners are advised to update immediately and consider web application firewalls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
