← WordPress Vulnerabilities
WordPress security by component

W3 Total Cache

W3 Total Cache improves WordPress content delivery through page caching, browser caching, asset optimization, and cache management features.

W3 Total Cache (w3-total-cache) is a WordPress plugin with 23 published CVE records in this archive. The latest tracked vulnerability was published Sep 05, 2026; the highest published CVSS base score is 10.

Plugin slug: w3-total-cache

CVE-2026-78438: W3 Total Cache comment processing permits unauthenticated stored XSS

W3 Total Cache through 2.10.5 can transform malicious comment content into executable script when Lazy Load Images and the non-default Process background images option are enabled. An unauthenticated commenter supplies the content; where moderation is enabled, execution begins after a moderator approves the comment and a visitor opens the affected page.

PublishedSep 05, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for w3-total-cache
Safe version
Sep 05, 2026 CVE-2026-78438
W3 Total Cache comment processing permits unauthenticated stored XSS
W3 Total Cache through 2.10.5 can transform malicious comment content into executable script when Lazy Load Images and the non-default Process background images option are enabled. An unauthenticated commenter supplies the content; where moderation is enabled, execution begins after a moderator approves the comment and a visitor opens the affected page.
See mitigation notes
CVE7.2
NVDPending
Aug 19, 2026 CVE-2026-18051
W3 Total Cache request paths permit unauthenticated arbitrary file overwrite
W3 Total Cache before 2.10.5 does not validate the request path used to construct cache-file names. An unauthenticated attacker can write into any existing server directory and overwrite the target name; on Apache the flaw can overwrite .htaccess, break the site and remove hardening rules.
2.10.5
CVE10.0
NVDPending
Aug 14, 2026 CVE-2026-18109
W3 Total Cache lazy loading permits unauthenticated stored XSS
W3 Total Cache through 2.10.3 permits an unauthenticated commenter to store a malicious Comment Author Name that can execute when Lazy Load Images is enabled. UserExperience_LazyLoad_Mutator::tag_img_content_replace() used regular-expression replacements that could treat src= text inside a quoted attribute as a real image attribute and re-emit crafted author content unsafely during lazy-load rewriting. The payload executes when a visitor, including an administrator, views the affected page. Version 2.10.4 restricts replacements to top-level quoted attributes and protects intermediate content with an encoded placeholder. The exact reporter payload is not disclosed.
2.10.4
CVE7.2
NVDPending
Aug 06, 2026 CVE-2026-66695
W3 Total Cache permits unauthenticated path traversal
W3 Total Cache 2.10.2 and earlier permits unauthenticated path traversal. Attacker-controlled path data reaches a filesystem operation without adequate restriction, but.
2.10.3
CVE6.5
NVDPending
Jul 11, 2026 CVE-2026-9282
W3 Total Cache: Filesystem traversal
W3 Total Cache is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 2.9.4.
See mitigation notes
CVE7.5
NVDPending
Jul 02, 2026 CVE-2026-57623
W3 Total Cache: Code execution
W3 Total Cache is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 2.9.4.
2.10.0
CVE9.0
NVDPending
Jun 17, 2026 CVE-2026-39595
W3 Total Cache: Broken access control
W3 Total Cache is affected by broken access control. Exploitation requires an authenticated author account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 2.9.1.
2.9.2
CVE4.7
NVDPending
Apr 02, 2026 CVE-2026-5032
W3 Total Cache: Code execution
W3 Total Cache is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 2.9.3.
See mitigation notes
CVE7.5
NVDPending
Mar 05, 2026 CVE-2026-27384
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.0
NVDPending
Nov 17, 2025 CVE-2025-9501
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.0
NVDPending
Jan 14, 2025 CVE-2024-12365
W3 Total Cache: Sensitive information exposure
W3 Total Cache is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE8.5
NVDPending
Jan 14, 2025 CVE-2024-12008
W3 Total Cache: Cross-site request forgery
W3 Total Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.3
NVD7.5
Jan 14, 2025 CVE-2024-12006
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 25, 2024 CVE-2023-5359
W3 Total Cache: Sensitive information exposure
W3 Total Cache is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE3.7
NVD7.5
Jul 19, 2021 CVE-2021-24452
W3 Total Cache: Cross-site scripting
W3 Total Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Jul 19, 2021 CVE-2021-24436
W3 Total Cache: Cross-site scripting
W3 Total Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Jul 12, 2021 CVE-2021-24427
W3 Total Cache: Cross-site scripting
W3 Total Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
Nov 22, 2019 CVE-2012-6079
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5
Nov 22, 2019 CVE-2012-6078
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5
Nov 22, 2019 CVE-2012-6077
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5
Apr 01, 2019 CVE-2019-6715
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5
Dec 24, 2014 CVE-2014-9414
W3 Total Cache: Cross-site request forgery
W3 Total Cache is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD6.8
Dec 19, 2014 CVE-2014-8724
W3 Total Cache: Cross-site scripting
W3 Total Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.3