CVE-2024-12008

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 200

Summary

CVE-2024-12008 is a newly disclosed vulnerability affecting the W3 Total Cache plugin for WordPress. In versions up to and including 2.8.1, this plugin is susceptible to Information Exposure due to publicly exposed debug log files. Attackers can exploit this vulnerability to gain access to potentially sensitive information, including nonce values that may be used for CSRF attacks. This issue only affects installations where the debug feature is enabled, which is disabled by default. WordPress users are advised to upgrade to the latest version of W3 Total Cache to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share