CVE-2024-12006
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: security@wordfence.com (Secondary)
Description
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin extensions.
Affected (1)
Products: Boldgrid: W3 Total Cache
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.2 |
References (6)
Source: security@wordfence.com
Patch
Source: security@wordfence.com
Patch
https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.8.0/Extensions_Plugin_Admin.php#L60
Source: security@wordfence.com
Patch
https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.8.0/Extensions_Plugin_Admin.php#L63
Source: security@wordfence.com
Patch
Source: security@wordfence.com
Patch
Source: security@wordfence.com
Third Party Advisory
Timeline
No history available yet.