CVE-2024-12006: W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin extensions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12006?
CVE-2024-12006 is a medium severity vulnerability that allows unauthorized modification of data in the W3 Total Cache plugin.
How do I fix CVE-2024-12006?
To fix CVE-2024-12006, update the W3 Total Cache plugin to version 2.8.2 or later.
What versions of the W3 Total Cache plugin are affected by CVE-2024-12006?
All versions of the W3 Total Cache plugin up to and including 2.8.1 are affected by CVE-2024-12006.
Can CVE-2024-12006 be exploited by authenticated users?
No, CVE-2024-12006 can be exploited by unauthenticated attackers due to a missing capability check.
What actions can an attacker perform by exploiting CVE-2024-12006?
An attacker can deactivate the W3 Total Cache plugin and potentially execute other unauthorized actions.