Home/Product/boldgrid w3 total cache
Product

boldgrid w3 total cache

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-12365
< 2.8.2
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w
8.5HIGH
CVE-2024-12008
< 2.8.2
The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through
5.3MEDIUM
CVE-2024-12006
< 2.8.2
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on se
5.3MEDIUM
CVE-2023-5359
< 2.7.6
The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 vi
3.7LOW
CVE-2021-24452
< 2.1.5
The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extensio
6.1MEDIUM
CVE-2021-24436
< 2.1.4
The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability w
6.1MEDIUM
CVE-2021-24427
< 2.1.3
The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege user
4.8MEDIUM
CVE-2013-2010
<= 0.9.2.8
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
9.8CRITICAL
CVE-2012-6079
< 0.9.2.5
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this informa
7.5HIGH
CVE-2012-6078
< 0.9.2.5
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
7.5HIGH
CVE-2012-6077
< 0.9.2.5
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database ca
7.5HIGH
CVE-2019-6715
< 0.9.4
pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the Subscr
7.5HIGH
CVE-2014-9414
<= 0.9.4
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to con
CVE-2014-8724
<= 0.9.4
Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, al
threatengine.sh