VendorsBoldGridw3_total_cacheall versions
Vulnerabilities

BoldGrid W3 Total Cache for WordPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2013-2010
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
Published 2020-02-12 · Modified
9.81 PoCEPSS 0.739
CVE-2024-12365
W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery
Published 2025-01-14 · Analyzed
8.5EPSS 0.018
CVE-2019-6715
pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.
Published 2019-04-01 · Modified
7.5EPSS 0.194
CVE-2012-6077
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
Published 2019-11-22 · Modified
7.5EPSS 0.054
CVE-2012-6078
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
Published 2019-11-22 · Modified
7.5EPSS 0.023
CVE-2024-12008
W3 Total Cache <= 2.8.1 Information Exposure via Log Files
Published 2025-01-14 · Analyzed
7.5EPSS 0.023
CVE-2012-6079
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.
Published 2019-11-22 · Modified
7.5EPSS 0.021
CVE-2023-5359
W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext
Published 2024-09-24 · Analyzed
7.5EPSS 0.008
CVE-2014-9414
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parameter and an empty _wpnonce parameter in the w3tc_mobile page to wp-admin/admin.php.
Published 2014-12-24 · Modified
6.8EPSS 0.014
CVE-2021-24452
W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context)
Published 2021-07-19 · Modified
6.1EPSS 0.019
CVE-2021-24436
W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context)
Published 2021-07-19 · Modified
6.1EPSS 0.019
CVE-2024-12006
W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation
Published 2025-01-14 · Analyzed
5.3EPSS 0.005
CVE-2021-24427
W3 Total Cache < 2.1.3 - Authenticated Stored XSS
Published 2021-07-12 · Modified
4.8EPSS 0.006
CVE-2014-8724
Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the "Cache key" in the HTML-Comments, as demonstrated by the PATH_INFO to the default URI.
Published 2014-12-19 · Modified
4.3EPSS 0.021