CVE-2024-12365 is a high-severity vulnerability affecting the W3 Total Cache plugin for WordPress, impacting all versions up to and including 2.8.1. It allows authenticated attackers with Subscriber-level access to bypass capability checks, obtain nonce values, and perform unauthorized actions. This can lead to information disclosure, consumption of service plan limits, and server-side request forgery (SSRF) to internal services, including cloud instance metadata. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 2.8.1CPE match | cpe:2.3:a:boldgrid:w3_total_cache:*:*:*:*:*:wordpress:*:* | ||
< 2.8.2CPE matchmatch criteria | cpe:2.3:a:boldgrid:w3_total_cache:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.