The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin extensions.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 14 Jan 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin extensions. | |
Title | W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-01-14T07:05:40.976Z
Updated: 2025-01-14T14:47:20.679Z
Reserved: 2024-12-01T10:13:08.652Z
Link: CVE-2024-12006
Vulnrichment
Updated: 2025-01-14T14:47:11.423Z
NVD
Status : Received
Published: 2025-01-14T07:15:25.633
Modified: 2025-01-14T07:15:25.633
Link: CVE-2024-12006
Redhat
No data.