WordPress security by component
W3 Total Cache
Plugin description
W3 Total Cache is a WordPress component with 19 published CVE records in this archive. The latest tracked vulnerability was published Jul 11, 2026; the highest CVE/CNA score is 9.
Plugin slug:
w3-total-cacheLatest vulnerability
CVE-2026-9282: W3 Total Cache: Filesystem traversal
W3 Total Cache is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 2.9.4.
| Safe version |
|
||
|---|---|---|---|
| Jul 11, 2026 |
CVE-2026-9282
W3 Total Cache: Filesystem traversal
W3 Total Cache is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 2.9.4.
|
> 2.9.4 |
CVE7.5
NVDPending
|
| Jul 02, 2026 |
CVE-2026-57623
W3 Total Cache: Code execution
W3 Total Cache is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 2.9.4.
|
2.10.0 |
CVE9.0
NVDPending
|
| Jun 17, 2026 |
CVE-2026-39595
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.9.1.
|
2.9.2 |
CVE4.7
NVDPending
|
| Apr 02, 2026 |
CVE-2026-5032
W3 Total Cache: Code execution
W3 Total Cache is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 2.9.3.
|
> 2.9.3 |
CVE7.5
NVDPending
|
| Mar 05, 2026 |
CVE-2026-27384
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.0
NVDPending
|
| Nov 17, 2025 |
CVE-2025-9501
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.0
NVDPending
|
| Jan 14, 2025 |
CVE-2024-12365
W3 Total Cache: Sensitive information exposure
W3 Total Cache is affected by sensitive information exposure. Exploitation requires at least subscriber-level access. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Jan 14, 2025 |
CVE-2024-12008
W3 Total Cache: Cross-site request forgery
W3 Total Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Jan 14, 2025 |
CVE-2024-12006
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 25, 2024 |
CVE-2023-5359
W3 Total Cache: Sensitive information exposure
W3 Total Cache is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE3.7
NVD7.5
|
| Jul 19, 2021 |
CVE-2021-24452
W3 Total Cache: Cross-site scripting
W3 Total Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jul 19, 2021 |
CVE-2021-24436
W3 Total Cache: Cross-site scripting
W3 Total Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jul 12, 2021 |
CVE-2021-24427
W3 Total Cache: Cross-site scripting
W3 Total Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Nov 22, 2019 |
CVE-2012-6079
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Nov 22, 2019 |
CVE-2012-6078
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Nov 22, 2019 |
CVE-2012-6077
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Apr 01, 2019 |
CVE-2019-6715
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Dec 24, 2014 |
CVE-2014-9414
W3 Total Cache: Cross-site request forgery
W3 Total Cache is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.8
NVD6.8
|
| Dec 19, 2014 |
CVE-2014-8724
W3 Total Cache: Cross-site scripting
W3 Total Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVD4.3
|