HomeWordPress vulnerabilitiesW3 Total Cache
W3 Total Cache vulnerabilities
W3 Total Cache has 17 known vulnerabilities in this database. The most recent published record is dated 2 Oct 2026.
- Known vulnerabilities
- 17
- Active installs
- 900,000+
- Latest version
- 2.10.6
- Last updated
- 4 Sep 2026
- Most recent
- 2 Oct 2026
No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-87920 | High 7.2 | Up to 2.10.6 | No fixed version yet | 5 d ago |
| Cross-site scripting (XSS) CVE-2026-78438 | High 7.2 | Up to 2.10.5 | Fixed in a later version (latest 2.10.6) | 5 Sep 2026 |
| Path traversal CVE-2026-18051 | Critical 10.0 | Before 2.10.5 | Fixed in 2.10.5 | 19 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-18109 | High 7.2 | Up to 2.10.3 | Fixed in a later version (latest 2.10.6) | 14 Aug 2026 |
| Path traversal CVE-2026-9282 | High 7.5 | Up to 2.9.4 | Fixed in a later version (latest 2.10.6) | 11 Jul 2026 |
| Remote code execution CVE-2026-5032 | High 7.5 | Up to 2.9.3 | Fixed in a later version (latest 2.10.6) | 2 Apr 2026 |
| Remote code execution CVE-2025-9501 | Critical 9.0 | Before 2.8.13 | Fixed in 2.8.13 | 17 Nov 2025 |
| Broken access control CVE-2024-12365 | High 8.5 | Before 2.8.2 | Fixed in 2.8.2 | 14 Jan 2025 |
| Broken access control CVE-2024-12006 | Medium 5.3 | Before 2.8.2 | Fixed in 2.8.2 | 14 Jan 2025 |
| Cross-site request forgery (CSRF) CVE-2024-12008 | Medium 5.3 | Before 2.8.2 | Fixed in 2.8.2 | 14 Jan 2025 |
| Sensitive data exposure CVE-2023-5359 | Low 3.7 | Before 2.7.6 | Fixed in 2.7.6 | 25 Sep 2024 |
| Cross-site scripting (XSS) CVE-2021-24436 | Medium 6.1 | Before 2.1.4 | Fixed in 2.1.4 | 19 Jul 2021 |
| Cross-site scripting (XSS) CVE-2021-24452 | Medium 6.1 | Before 2.1.5 | Fixed in 2.1.5 | 19 Jul 2021 |
| Cross-site scripting (XSS) CVE-2021-24427 | Medium 4.8 | Before 2.1.3 | Fixed in 2.1.3 | 12 Jul 2021 |
| Security weakness CVE-2019-6715 | High 7.5 | Before 0.9.4 | Fixed in 0.9.4 | 1 Apr 2019 |
| Cross-site request forgery (CSRF) CVE-2014-9414 | Not scored | Up to 0.9.4 | Fixed in a later version (latest 2.10.6) | 24 Dec 2014 |
| Cross-site scripting (XSS) CVE-2014-8724 | Not scored | Up to 0.9.4 | Fixed in a later version (latest 2.10.6) | 19 Dec 2014 |
Read the published descriptions
- CVE-2026-87920, 2 Oct 2026
- The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, and including, 2.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the 'Remove query strings from static resources' option is enabled in W3 Total Cache, as mutate_url() must strip the '?' delimiter and everything following it - including the closing quote of the outer attribute - to break the attribute boundary. CVE record
- CVE-2026-78438, 5 Sep 2026
- The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the "Lazy Load Images" feature with "Process background images" to be enabled, and the malicious comment to be approved by a moderator before execution is triggered. CVE record
- CVE-2026-18051, 19 Aug 2026
- The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on. CVE record
- CVE-2026-18109, 14 Aug 2026
- The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step. CVE record
- CVE-2026-9282, 11 Jul 2026
- The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires enabling manual minify mode and supplying a manual-format minify filename so that the hash is empty and the f_array[] entries are not overwritten before reaching setupSources(). CVE record
- CVE-2026-5032, 2 Apr 2026
- The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains "W3 Total Cache", which causes raw mfunc/mclude dynamic fragment HTML comments - including the W3TC_DYNAMIC_SECURITY security token - to be rendered in the page source. This makes it possible for unauthenticated attackers to discover the value of the W3TC_DYNAMIC_SECURITY constant by sending a crafted User-Agent header to any page that contains developer-placed dynamic fragment tags, granted the site has the fragment caching feature enabled. With the leaked W3TC_DYNAMIC_SECURITY token, an attacker can craft valid mfunc tags to execute arbitrary PHP code on the server, achieving remote code execution. CVE record
- CVE-2025-9501, 17 Nov 2025
- The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post. CVE record
- CVE-2024-12365, 14 Jan 2025
- The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain the plugin's nonce value and perform unauthorized actions, resulting in information disclosure, service plan limits consumption as well as making web requests to arbitrary locations originating from the web application that can be used to query information from internal services, including instance metadata on cloud-based applications. CVE record
- CVE-2024-12006, 14 Jan 2025
- The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin extensions. CVE record
- CVE-2024-12008, 14 Jan 2025
- The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example, the log file may contain nonce values that can be used in further CSRF attacks. Note: the debug feature must be enabled for this to be a concern, and it is disabled by default. CVE record
- CVE-2023-5359, 25 Sep 2024
- The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account information in successful conditions. This would not impact the WordPress users site in any way. CVE record
- CVE-2021-24436, 19 Jul 2021
- The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise. CVE record
- CVE-2021-24452, 19 Jul 2021
- The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper escaping. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise. CVE record
- CVE-2021-24427, 12 Jul 2021
- The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue CVE record
- CVE-2019-6715, 1 Apr 2019
- pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data. CVE record
- CVE-2014-9414, 24 Dec 2014
- The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parameter and an empty _wpnonce parameter in the w3tc_mobile page to wp-admin/admin.php. CVE record
- CVE-2014-8724, 19 Dec 2014
- Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the "Cache key" in the HTML-Comments, as demonstrated by the PATH_INFO to the default URI. CVE record
What to do if you run W3 Total Cache
If you run W3 Total Cache, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new W3 Total Cache vulnerabilities
Free. We email you when a new vulnerability is published for W3 Total Cache, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.