Known CVE
WordPress W3 Total Cache <2.1.5 - Cross-Site Scripting
WordPress W3 Total Cache plugin before 2.1.5 is susceptible to cross-site scripting via the extension parameter in the Extensions dashboard, when the setting 'Anonymously track usage to improve product quality' is enabled. The parameter is output in a JavaScript context without proper escaping. This can allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.
CVE-2021-24452
Medium2021CVSS 6.1CWE-79
cve2021 · xss · wpscan · wordpress · wp-plugin · wp · w3-total-cache · auth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website