Skip to content
Noroxi

W3 Total Cache

w3-total-cache · plugin

Known security vulnerabilities for W3 Total Cache. Find out in seconds which version runs on your site with WP Lens.

14 known vulnerabilities

2 critical · 6 with public exploit code · latest Sep 5, 2026

Vulnerabilities

  • CVE-2026-57623

    WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerability

    Critical 9.0
  • CVE-2026-27384

    WordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerability

    Critical 9.0
  • CVE-2024-12365

    W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery

    High 8.5
  • CVE-2026-9282

    W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter

    High 7.5
  • CVE-2026-5032

    W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header

    High 7.5
  • CVE-2024-12008

    W3 Total Cache <= 2.8.1 Information Exposure via Log Files

    High 7.5
  • CVE-2023-5359

    W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext

    High 7.5
  • CVE-2026-78438

    W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator

    High 7.2
  • CVE-2026-18109

    W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name

    High 7.2
  • CVE-2014-9414

    The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross

    Medium 6.8
  • CVE-2026-66695

    WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability

    Medium 6.5
  • CVE-2024-12006

    W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation

    Medium 5.3
  • CVE-2026-39595

    WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerability

    Medium 4.7
  • CVE-2014-8724

    Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remot

    Medium 4.3

← Back to directory