W3speedster is a web-performance optimization platform whose vulnerability footprint centers on cross-site request forgery (CSRF) weaknesses in its core product, a pattern typical of session-based web applications lacking robust anti-CSRF token enforcement. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by W3speedster over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8512CRITICAL The W3SPEEDSTER plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.26 via the 'script' parameter of the hookBeforeStartOptimization | Oct 30, 2024 | 9.1 | 26 | NO | NO |
CVE-2024-52392MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in w3speedster W3SPEEDSTER w3speedster-wp.This issue affects W3SPEEDSTER: from n/a through <= 7.25. | Nov 19, 2024 | 6.5 | 18 | NO | NO |
CVE-2025-23765MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in w3speedster W3SPEEDSTER w3speedster-wp allows Cross Site Request Forgery.This issue affects W3SPEEDSTER: from n/a through <= 7.33 | Jan 16, 2025 | 4.3 | 15 | NO | NO |
CVE-2024-24708MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER.This issue affects W3SPEEDSTER: from n/a through 7.19. | Feb 29, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by W3speedster.
Media articles that mention a CVE ID that affects a product developed by W3speedster — matched by CVE ID, not by vendor name.