Over a million WordPress sites exposed to attack from W3 Total Cache plugin bug


  • Vulnerability was discovered in the W3 Total Cache WordPress plugin, allowing for data exposure and more
  • It affects all versions up to 2.8.2, which was released as a response
  • Hundreds of thousands of WordPress sites are still vulnerable

W3 Total Cache, a popular WordPress website performance optimization plugin, reportedly carried a high-severity vulnerability that allowed attackers to access sensitive information, abuse service plan limits, and perform unauthorized actions.

The vulnerability is tracked as CVE-2024-12365 and has a severity rating of 8.5/10 (high). It occurs due to a missing capability check in a function and affects all versions up to and including 2.8.1.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top