CVE · High

CVE-2024-12365 — W3 Total Cache [w3-total-cache] < 2.8.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-12365 W3 Total Cache [w3-total-cache] < 2.8.2 Missing Authorization High 8.5 < 2.8.2 2.8.2 2025-01-13

CVE-2024-12365

W3 Total Cache versions 2.8.1 and earlier contain a capability check vulnerability in the is_w3tc_admin_page function that allows authenticated users with subscriber-level permissions or higher to extract the plugin's nonce and execute unauthorized operations. Attackers exploiting this flaw can expose sensitive information, consume service plan quotas, and make arbitrary web requests from the affected server to internal services or cloud metadata endpoints.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.