Tech

Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw

Share
Share


  • Vulnerability was discovered in W3 Total Cache WordPress plugin, allowing for data exposure, and more
  • It affects all versions up to 2.8.2, which was released in response
  • Hundreds of thousands of WordPress websites are still vulnerable

W3 Total Cache, a popular website performance optimization WordPress plugin, reportedly carried a high-severity vulnerability which allowed attackers to access sensitive information, abuse service plan limits, and run unauthorized actions.

The vulnerability is tracked as CVE-2024-12365, and has a severity score of 8.5/10 (high). It occurs due to a missing capability check in a function, and affects all versions up to, and including, 2.8.1.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
YouTube Music listeners are getting a very handy new volume control
Tech

YouTube Music listeners are getting a very handy new volume control

A ‘consistent volume’ setting is spotted in YouTube Music It should prevent...

Quordle hints and answers for Sunday, April 20 (game #1182)
Tech

Quordle hints and answers for Sunday, April 20 (game #1182)

Looking for a different day? A new Quordle puzzle appears at midnight...