CVE · Medium

CVE-2024-12006 — W3 Total Cache [w3-total-cache] < 2.8.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-12006 W3 Total Cache [w3-total-cache] < 2.8.2 Missing Authorization Medium 5.3 < 2.8.2 2.8.2 2025-01-13

CVE-2024-12006

The W3 Total Cache WordPress plugin through version 2.8.1 contains a flaw where certain functions lack proper permission validation, allowing unauthenticated users to perform privileged actions. Attackers exploiting this vulnerability could disable the main plugin or toggle the activation status of its extensions without requiring valid credentials.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.