CVE-2019-6715: Boldgrid w3 Total Cache

High severity, CVSS 7.5. EPSS: 19.4% chance of exploitation in the next 30 days.

pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.

Affected products

  • Boldgrid w3 Total Cache: before 0.9.4 (fixed in 0.9.4)

Published 2019-04-01. Last modified 2026-06-17.