CVE-2024-12365
W3 Total Cache versions 2.8.1 and earlier contain a capability check vulnerability in the is_w3tc_admin_page function that allows authenticated users with subscriber-level permissions or higher to extract the plugin's nonce and execute unauthorized operations. Attackers exploiting this flaw can expose sensitive information, consume service plan quotas, and make arbitrary web requests from the affected server to internal services or cloud metadata endpoints.
Based on public CVE data (MITRE/NVD).