İçeriğe atla
Noroxi

W3 Total Cache

w3-total-cache · eklenti

W3 Total Cache için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.

14 bilinen açık

2 kritik · 6 kayıt için istismar kodu yayımlanmış · son kayıt 5 Eyl 2026

Güvenlik açıkları

  • CVE-2026-57623

    WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerability

    Kritik 9.0
  • CVE-2026-27384

    WordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerability

    Kritik 9.0
  • CVE-2024-12365

    W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery

    Yüksek 8.5
  • CVE-2026-9282

    W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter

    Yüksek 7.5
  • CVE-2026-5032

    W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header

    Yüksek 7.5
  • CVE-2024-12008

    W3 Total Cache <= 2.8.1 Information Exposure via Log Files

    Yüksek 7.5
  • CVE-2023-5359

    W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext

    Yüksek 7.5
  • CVE-2026-78438

    W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator

    Yüksek 7.2
  • CVE-2026-18109

    W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name

    Yüksek 7.2
  • CVE-2014-9414

    The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross

    Orta 6.8
  • CVE-2026-66695

    WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability

    Orta 6.5
  • CVE-2024-12006

    W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation

    Orta 5.3
  • CVE-2026-39595

    WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerability

    Orta 4.7
  • CVE-2014-8724

    Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remot

    Orta 4.3

← Dizine dön