WordPress security by component
W3 Total Cache
Plugin description
W3 Total Cache improves WordPress content delivery through page caching, browser caching, asset optimization, and cache management features.
W3 Total Cache (w3-total-cache) is a WordPress plugin with 23 published CVE records in this archive. The latest tracked vulnerability was published Sep 05, 2026; the highest published CVSS base score is 10.
Plugin slug:
w3-total-cacheLatest vulnerability
CVE-2026-78438: W3 Total Cache comment processing permits unauthenticated stored XSS
W3 Total Cache through 2.10.5 can transform malicious comment content into executable script when Lazy Load Images and the non-default Process background images option are enabled. An unauthenticated commenter supplies the content; where moderation is enabled, execution begins after a moderator approves the comment and a visitor opens the affected page.
| Safe version |
|
||
|---|---|---|---|
| Sep 05, 2026 |
CVE-2026-78438
W3 Total Cache comment processing permits unauthenticated stored XSS
W3 Total Cache through 2.10.5 can transform malicious comment content into executable script when Lazy Load Images and the non-default Process background images option are enabled. An unauthenticated commenter supplies the content; where moderation is enabled, execution begins after a moderator approves the comment and a visitor opens the affected page.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Aug 19, 2026 |
CVE-2026-18051
W3 Total Cache request paths permit unauthenticated arbitrary file overwrite
W3 Total Cache before 2.10.5 does not validate the request path used to construct cache-file names. An unauthenticated attacker can write into any existing server directory and overwrite the target name; on Apache the flaw can overwrite .htaccess, break the site and remove hardening rules.
|
2.10.5 |
CVE10.0
NVDPending
|
| Aug 14, 2026 |
CVE-2026-18109
W3 Total Cache lazy loading permits unauthenticated stored XSS
W3 Total Cache through 2.10.3 permits an unauthenticated commenter to store a malicious Comment Author Name that can execute when Lazy Load Images is enabled. UserExperience_LazyLoad_Mutator::tag_img_content_replace() used regular-expression replacements that could treat src= text inside a quoted attribute as a real image attribute and re-emit crafted author content unsafely during lazy-load rewriting. The payload executes when a visitor, including an administrator, views the affected page. Version 2.10.4 restricts replacements to top-level quoted attributes and protects intermediate content with an encoded placeholder. The exact reporter payload is not disclosed.
|
2.10.4 |
CVE7.2
NVDPending
|
| Aug 06, 2026 |
CVE-2026-66695
W3 Total Cache permits unauthenticated path traversal
W3 Total Cache 2.10.2 and earlier permits unauthenticated path traversal. Attacker-controlled path data reaches a filesystem operation without adequate restriction, but.
|
2.10.3 |
CVE6.5
NVDPending
|
| Jul 11, 2026 |
CVE-2026-9282
W3 Total Cache: Filesystem traversal
W3 Total Cache is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 2.9.4.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jul 02, 2026 |
CVE-2026-57623
W3 Total Cache: Code execution
W3 Total Cache is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 2.9.4.
|
2.10.0 |
CVE9.0
NVDPending
|
| Jun 17, 2026 |
CVE-2026-39595
W3 Total Cache: Broken access control
W3 Total Cache is affected by broken access control. Exploitation requires an authenticated author account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 2.9.1.
|
2.9.2 |
CVE4.7
NVDPending
|
| Apr 02, 2026 |
CVE-2026-5032
W3 Total Cache: Code execution
W3 Total Cache is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 2.9.3.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Mar 05, 2026 |
CVE-2026-27384
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.0
NVDPending
|
| Nov 17, 2025 |
CVE-2025-9501
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.0
NVDPending
|
| Jan 14, 2025 |
CVE-2024-12365
W3 Total Cache: Sensitive information exposure
W3 Total Cache is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Jan 14, 2025 |
CVE-2024-12008
W3 Total Cache: Cross-site request forgery
W3 Total Cache is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Jan 14, 2025 |
CVE-2024-12006
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 25, 2024 |
CVE-2023-5359
W3 Total Cache: Sensitive information exposure
W3 Total Cache is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE3.7
NVD7.5
|
| Jul 19, 2021 |
CVE-2021-24452
W3 Total Cache: Cross-site scripting
W3 Total Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jul 19, 2021 |
CVE-2021-24436
W3 Total Cache: Cross-site scripting
W3 Total Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jul 12, 2021 |
CVE-2021-24427
W3 Total Cache: Cross-site scripting
W3 Total Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Nov 22, 2019 |
CVE-2012-6079
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Nov 22, 2019 |
CVE-2012-6078
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Nov 22, 2019 |
CVE-2012-6077
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Apr 01, 2019 |
CVE-2019-6715
W3 Total Cache: A security weakness
W3 Total Cache is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Dec 24, 2014 |
CVE-2014-9414
W3 Total Cache: Cross-site request forgery
W3 Total Cache is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD6.8
|
| Dec 19, 2014 |
CVE-2014-8724
W3 Total Cache: Cross-site scripting
W3 Total Cache is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.3
|