Boldgrid
Boldgrid W3 Total Cache: vulnerabilidades y CVE
Boldgrid W3 Total Cache tiene 22 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses8
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-78438 | Alta (7.2) | 0.50% | — | 5 sept 2026 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input… |
| CVE-2026-18051 | Crítica (10) | 0.57% | — | 19 ago 2026 | The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the… |
| CVE-2026-18109 | Alta (7.2) | 0.43% | — | 14 ago 2026 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This… |
| CVE-2026-9282 | Alta (7.5) | 2.9% | — | 11 jul 2026 | The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the… |
| CVE-2026-39595 | Media (4.7) | 0.29% | — | 17 jun 2026 | Author Broken Access Control in W3 Total Cache <= 2.9.1 versions. |
| CVE-2026-5032 | Alta (7.5) | 2.7% | — | 2 abr 2026 | The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the… |
| CVE-2026-27384 | Crítica (9) | 0.43% | — | 5 mar 2026 | Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects W3 Total Cache: from n/a… |
| CVE-2025-9501 | Crítica (9) | 23% | — | 17 nov 2025 | The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious… |
| CVE-2024-12365 | Alta (8.5) | 1.8% | — | 14 ene 2025 | The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it… |
| CVE-2024-12008 | Alta (7.5) | 2.3% | — | 14 ene 2025 | The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers… |
| CVE-2024-12006 | Media (5.3) | 0.51% | — | 14 ene 2025 | The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for… |
| CVE-2023-5359 | Alta (7.5) | 0.81% | — | 25 sept 2024 | The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source.… |
| CVE-2021-24452 | Media (6.1) | 1.9% | — | 19 jul 2021 | The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve… |
| CVE-2021-24436 | Media (6.1) | 1.9% | — | 19 jul 2021 | The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an… |
| CVE-2021-24427 | Media (4.8) | 0.62% | — | 12 jul 2021 | The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an… |
| CVE-2013-2010 | Crítica (9.8) | 74% | — | 12 feb 2020 | WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability |
| CVE-2012-6079 | Alta (7.5) | 2.1% | — | 22 nov 2019 | W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys. |
| CVE-2012-6078 | Alta (7.5) | 2.3% | — | 22 nov 2019 | W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes. |
| CVE-2012-6077 | Alta (7.5) | 5.4% | — | 22 nov 2019 | W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files. |
| CVE-2019-6715 | Alta (7.5) | 19% | — | 1 abr 2019 | pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data. |
| CVE-2014-9414 | Media (6.8) | 1.4% | — | 24 dic 2014 | The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of… |
| CVE-2014-8724 | Media (4.3) | 2.1% | — | 19 dic 2014 | Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the "Cache key" in the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.