# CVE-2024-12008: W3 Total Cache - Information Disclosure

> Live exploitation tracking for CVE-2024-12008 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2024-12008

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 5.3
- **Public exploit available:** Yes
- **Affected products:** Boldgrid W3 Total Cache
- **Weaknesses:** CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor)
- **Tags:** wordpress, cms

## Description

The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example, the log file may contain nonce values that can be used in further CSRF attacks.
Note: the debug feature must be enabled for this to be a concern, and it is disabled by default.

## CrowdSec analysis

[CVE-2024-12008](https://euvd.enisa.europa.eu/vulnerability/CVE-2024-12008) is an information disclosure vulnerability in the W3 Total Cache plugin for WordPress, affecting all versions up to 2.8.1. When the debug feature is enabled, unauthenticated attackers can access a publicly exposed debug log file, potentially revealing sensitive information such as nonce values. This exposure could facilitate further attacks, including cross-site request forgery (CSRF), if exploited.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

CrowdSec network observations suggest that most exploitation of CVE-2024-12008 involves focused reconnaissance to identify viable targets. Attackers typically tailor their campaigns based on system exposure and configuration. It is unlikely that a given attack is accidental.
Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2024-12008. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.

Attackers exploit this vulnerability by directly accessing log files such as `/wp-content/cache/log/000000/pagecache.log` and `/wp-content/cache/log/000000/minify.log`, exposing sensitive information from W3 Total Cache plugin debug logs. These endpoints are targeted to retrieve data that may aid in further attacks, such as nonce values or credentials.

## Timeline

- 2025-01-14: CVE Published. CVE-2024-12008 is published to NVD.
- 2026-06-24: Rule Released. CrowdSec releases a rule to detect CVE-2024-12008 exploitation attempts against the CrowdSec Network.
- 2026-06-25: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2024-12008 for the first time.

## References

- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-12008.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2024-12008) follows observed exploitation activity for CVE-2024-12008. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
