W3 Total Cache Information Exposure Vulnerability

Vulnerability

A vulnerability allowing information exposure has been identified in the W3 Total Cache plugin for WordPress, affecting all versions through 2.8.1. The issue arises from a publicly accessible debug log file that can reveal sensitive information, such as nonce values, which could be exploited in cross-site request forgery (CSRF) attacks. This vulnerability requires the debug feature to be enabled, which is off by default.

Impact

Exposing sensitive information to unauthorized users, which could include nonce values that might be used in CSRF attacks.

Remediation

Users can update to version 2.8.2 or a newer patched version to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.9
remediation
7.7
relevance
0.0
threat
3.9
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.