A serious vulnerability in the W3 Total Cache plugin could put more than a million WordPress sites at risk. The vulnerability could allow an attacker to gain access to various information, including metadata in cloud-based apps.

W3 Total Cache is a very useful plugin. It uses various caching techniquesto optimize a website's speed, reduce loading times, and improve SEO ranking.
See also: WP3.XYZ malware: Adds fraudulent administrators to 5,000+ WordPress sites
The vulnerability is tracked as CVE-2024-12365 and has been patched in the latest version of the plugin. However, hundreds of thousands of WordPress sites have not applied the update, leaving them vulnerable.
Wordfence has observed that the vulnerability is related to the 'is_w3tc_admin_page' function in all versions up to the latest, 2.8.2. Successful exploitation would allow access to the security nonce value of the W3 Total Cache plugin and perform unauthorized actions.
However, for exploitation to be possible, the attacker must be authenticated and have at least subscriber-level privileges (which is quite easy).
See also: WordPress Skimmers Steal Credit Cards Through Malicious JavaScript
The main risks arising from exploiting the CVE-2024-12365 vulnerability in the W3 Total Cache plugin are:
- Server-Side Request Forgery (SSRF): submitting web requests that could expose sensitive data, including metadata in cloud-based apps
- Disclosure of information
- Service abuse: consuming cache service limits, which affects website performance and can create increased costs
Overall, attackers could use the WordPress website infrastructure to forward requests to other services and use the information collected to carry out further attacks.
Users of the plugin are urged to upgrade to the latest version, 2.8.2, which addresses the vulnerability.
Download statistics indicate that around 150,000 websites have installed the plugin since the latest update was released, but hundreds of thousands of WordPress sites remain vulnerable.
See also: Fancy Product Designer: Two critical vulnerabilities in WordPress plugin
WordPress Security
WordPress website security requires a multi-pronged approach to protect against potential threats. One of the key strategies includes regularly updating plugins and themes (e.g. W3 Total Cache) to ensure that any security vulnerabilities have been patched. Using strong passwords and enabling two-factor authentication adds an extra layer of security. Additionally, regularly backing up your website can protect data in the event of an attack.
It is also recommended to install a powerful security plugin that offers features such as firewall protection, malware scanning, and brute force attack prevention.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
By implementing these measures, you can significantly improve the security of your WordPress website.
See also: Woffice: Vulnerabilities in WordPress theme – Update now!

Importance of WordPress protection
Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.
Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.
Source: www.bleepingcomputer.com
