W3 Total Cache
w3-total-cache · plugin
Known security vulnerabilities for W3 Total Cache. Find out in seconds which version runs on your site with WP Lens.
14 known vulnerabilities
2 critical · 6 with public exploit code · latest Sep 5, 2026
Vulnerabilities
- Critical 9.0
WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerability
- Critical 9.0
WordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerability
- High 8.5
W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery
- High 7.5
W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter
- High 7.5
W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header
- High 7.5
W3 Total Cache <= 2.8.1 Information Exposure via Log Files
- High 7.5
W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext
- High 7.2
W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator
- High 7.2
W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name
- Medium 6.8
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross
- Medium 6.5
WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability
- Medium 5.3
W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation
- Medium 4.7
WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerability
- Medium 4.3
Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remot