More than a million WordPress sites exposed to W3 Total Cache plugin attacks


  • Vulnerability discovered in W3 Total Cache WordPress plugin, allowing data exposure and more
  • This affects all versions up to 2.8.2, which was released in response
  • Hundreds of thousands of WordPress sites are still vulnerable

W3 Total Cache, a popular website performance optimization WordPress plugin, reportedly has a high-severity vulnerability that would allow attackers to access sensitive information, abuse service plan limits, and execute actions unauthorized.

The vulnerability is tracked as CVE-2024-12365 and has a severity score of 8.5/10 (high). This occurs due to a missing capability check in a function and affects all versions up to and including 2.8.1.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top