Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

W3 Total Cache — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in W3 Total Cache, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the WordPress plugin W3 Total Cache, developed by BoldPress, focusing on specific weakness classes and security tags. The collection covers historical security disclosures associated with this product, spanning the period from its initial public release through the most recent advisory updates. Visitors can use this aggregation to track vendor-issued security advisories, analyze recurring weakness categories such as cross-site scripting or insufficient access control, and review the complete vulnerability history of the plugin. The data is organized by date and severity to facilitate trend analysis and comparative assessment against other WordPress caching solutions. No specific CVE identifiers are listed; instead, the page emphasizes pattern recognition over individual incident details. This resource serves security engineers, site administrators, and researchers who need a consolidated view of past exposures without navigating multiple vendor communication channels.

Vendor: BoldGrid

CVE ID Title CVSS Severity Published
CVE-2026-87920 W3 Total Cache <= 2.10.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content CWE-79 7.2 High 2026-10-02
CVE-2026-78438 W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator CWE-79 7.2 High 2026-09-05
CVE-2026-18051 W3 Total Cache < 2.10.5 - Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page Cache Key - - 2026-08-19
CVE-2026-18109 W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name CWE-79 7.2 High 2026-08-14
CVE-2026-66695 WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability CWE-35 6.5 Medium 2026-08-06
CVE-2026-9282 W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter CWE-22 7.5 High 2026-07-11
CVE-2026-57623 WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerability CWE-1284 9.0 Critical 2026-07-02
CVE-2026-39595 WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerability CWE-862 4.7 Medium 2026-06-17
CVE-2026-5032 W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header CWE-200 7.5 High 2026-04-02
CVE-2026-27384 WordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerability CWE-1284 9.0 Critical 2026-03-05
CVE-2025-9501 W3 Total Cache < 2.8.13 - Unauthenticated Command Injection 9.8AI Critical AI 2025-11-17
CVE-2024-12008 W3 Total Cache <= 2.8.1 Information Exposure via Log Files CWE-200 5.3 Medium 2025-01-14
CVE-2024-12006 W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation CWE-862 5.3 Medium 2025-01-14
CVE-2024-12365 W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery CWE-862 8.5 High 2025-01-14
CVE-2023-5359 W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext CWE-200 3.7 Low 2024-09-24
CVE-2021-24452 W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context) CWE-79 6.1 - 2021-07-19
CVE-2021-24436 W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context) CWE-79 6.1 - 2021-07-19
CVE-2021-24427 W3 Total Cache < 2.1.3 - Authenticated Stored XSS CWE-79 4.8 - 2021-07-12

All 18 known CVE vulnerabilities affecting W3 Total Cache with full Chinese analysis, references, and POCs where available.