Tech

Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw

Share
Share


  • Vulnerability was discovered in W3 Total Cache WordPress plugin, allowing for data exposure, and more
  • It affects all versions up to 2.8.2, which was released in response
  • Hundreds of thousands of WordPress websites are still vulnerable

W3 Total Cache, a popular website performance optimization WordPress plugin, reportedly carried a high-severity vulnerability which allowed attackers to access sensitive information, abuse service plan limits, and run unauthorized actions.

The vulnerability is tracked as CVE-2024-12365, and has a severity score of 8.5/10 (high). It occurs due to a missing capability check in a function, and affects all versions up to, and including, 2.8.1.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
US asks judge to break up Google’s ad tech business
Tech

US asks judge to break up Google’s ad tech business

Google is facing a demand by the US government to break up...

New method quickly assesses underwater landslide risk for offshore turbines
Tech

New method quickly assesses underwater landslide risk for offshore turbines

Illustration of dynamic forces acting on monopile and tower, and soil-structure interaction....

Chuwi’s CoreBook X gets spec bump but lacks graphical muscle
Tech

Chuwi’s CoreBook X gets spec bump but lacks graphical muscle

Chuwi’s new CoreBook X features Intel i9-13900HK and 32GB RAM No discrete...