wordpress

W3 Total Cache plugin flaw exposes 1 million WordPress sites to attacks

Teilen:

A severe flaw in the W3 Total Cache plugin installed on more than one million WordPress sites could give attackers access to various information, including metadata on cloud-based apps.

The W3 Total Cache plugin uses multiple caching techniques to optimize a website’s speed, reduce load times, and generally improve its SEO ranking.

The flaw is tracked as CVE-2024-12365 despite the developer releasing a fix in the latest version of the product, hundreds of thousands of websites have still to install the patched variant.

Vulnerability details

Wordfence notes that the security issue is due to a missing capability check in the ‘is_w3tc_admin_page’ function in all versions up to the latest one, 2.8.2. This fault allows access to the plugin’s security nonce value and perform unauthorized actions.

Exploiting the vulnerability is possible if the attacker is authenticated and has at least subscriber-level, a condition that is easily met.

The main risks that arise from the exploitation of CVE-2024-12365 are:

  • Server-Side Request Forgery (SSRF): make web requests that could potentially expose sensitive data, including instance metadata on cloud-based apps
  • Information disclosure
  • Service abuse: consume cache service limits, which impact site performance and can generate increased costs

Regarding the real-world impact of this flaw, attackers could use the website’s infrastructure to proxy requests to other services and use the collected information to stage further attacks.

The best action for impacted users is to take is to upgrade to the latest version of W3 Total Cache version, 2.8.2, which addresses the vulnerability.

Download statistics from wordpress.org indicate that roughly 150,000 websites installed the plugin after the developer released the most recent update, leaving hundreds of thousands of WordPress sites still vulnerable.

As a general recommendations, website owners should avoid installing too many plugins and discard the products that are not absolutely necessary.

Additionally, a web application firewall could prove beneficial as it could identify and block exploitation attempts.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:14 am, Juni 8, 2025
Wetter-Symbol 10°C
L: 9° | H: 11°
broken clouds
Luftfeuchtigkeit: 91 %
Druck: 1009 mb
Wind: 5 mph NW
Windböe: 9 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 52%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:44 am
Sonnenuntergang: 9:14 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
9° | 11°°C 0.5 mm 50% 12 mph 90 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
10° | 19°°C 0.03 mm 3% 9 mph 87 % 1022 mb 0 mm/h
Di. Juni 10 10:00 pm
Wetter-Symbol
13° | 21°°C 0.33 mm 33% 9 mph 85 % 1020 mb 0 mm/h
Mi. Juni 11 10:00 pm
Wetter-Symbol
13° | 25°°C 0 mm 0% 9 mph 92 % 1020 mb 0 mm/h
Do. Juni 12 10:00 pm
Wetter-Symbol
18° | 26°°C 1 mm 100% 13 mph 93 % 1012 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
9° | 10°°C 0 mm 0% 10 mph 90 % 1010 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
10° | 11°°C 0 mm 0% 10 mph 81 % 1013 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 12 mph 53 % 1017 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 12 mph 44 % 1019 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 9 mph 51 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
15° | 15°°C 0.48 mm 48% 10 mph 74 % 1019 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0.5 mm 50% 8 mph 80 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
11° | 11°°C 0.03 mm 3% 7 mph 81 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,650.37
1.21%
Ethereum(ETH)
€2,214.90
1.87%
Fesseln(USDT)
€0.88
-0.02%
XRP(XRP)
€1.91
0.71%
Solana(SOL)
€131.58
1.41%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.162276
3.32%
Shiba Inu(SHIB)
€0.000011
2.34%
Pepe(PEPE)
€0.000011
3.90%
Peanut das Eichhörnchen(PNUT)
€0.234364
7.64%
Nach oben scrollen