logo

W3 Total Cache plugin flaw exposes 1 million WordPress sites to attacks

ID: e24993a6-9b40-5f3f-8a31-106f7715795e

STIX ID: report--e24993a6-9b40-5f3f-8a31-106f7715795e

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-01-16

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A critical vulnerability (CVE-2024-12365) in the W3 Total Cache WordPress plugin—caused by a missing capability check in the is_w3tc_admin_page function—allows authenticated users with subscriber-level access to perform SSRF and access sensitive information (including cloud instance metadata), potentially enabling further attacks; the developer fixed the issue in version 2.8.2, but hundreds of thousands of sites remain unpatched, so site owners are advised to update immediately and consider web application firewalls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.