Product
boldgrid w3 total cache
14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-12365
CVE-2024-12008
CVE-2024-12006
CVE-2023-5359
CVE-2021-24452
CVE-2021-24436
CVE-2021-24427
CVE-2013-2010
CVE-2012-6079
CVE-2012-6078
CVE-2012-6077
CVE-2019-6715
CVE-2014-9414
CVE-2014-8724
< 2.8.2
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w
< 2.8.2
The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through
< 2.8.2
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on se
< 2.7.6
The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 vi
< 2.1.5
The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extensio
< 2.1.4
The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability w
< 2.1.3
The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege user
<= 0.9.2.8
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
< 0.9.2.5
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this informa
< 0.9.2.5
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
< 0.9.2.5
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database ca
< 0.9.4
pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the Subscr
<= 0.9.4
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to con
<= 0.9.4
Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, al