Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-12006


The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin extensions.


Published

2025-01-14T07:15:25.633

Last Modified

2025-01-16T21:30:14.640

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application boldgrid w3_total_cache < 2.8.2 Yes

References