Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw




  • Vulnerability was discovered in W3 Total Cache WordPress plugin, allowing for data exposure, and more
  • It affects all versions up to 2.8.2, which was released in response
  • Hundreds of thousands of WordPress websites are still vulnerable

W3 Total Cache, a popular website performance optimization WordPress plugin, reportedly carried a high-severity vulnerability which allowed attackers to access sensitive information, abuse service plan limits, and run unauthorized actions.

The vulnerability is tracked as CVE-2024-12365, and has a severity score of 8.5/10 (high). It occurs due to a missing capability check in a function, and affects all versions up to, and including, 2.8.1.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *