plugin

W3 Total Cache Vulnerabilities

82 known security issues reported for the W3 Total Cache WordPress plugin. Most recent disclosed Aug 21, 2026.

2 critical 19 high 13 medium 2 low

Running W3 Total Cache on your site? Check whether your installed version is affected.

Scan your site free

W3 Total Cache < 2.10.5 - Unauthenticated Path Traversal

high

The W3 Total Cache plugin for WordPress is vulnerable to Path Traversal in all versions up to 2.10.5. This is due to insufficient validation of a user supplied path. This makes it possible for unauthenticated attackers to access files and directories outside of the intended directory.

CVSS:
7.5
Affected:
up to 2.10.5
Fixed in:
2.10.5
Disclosed:
Aug 21, 2026

CVE-2026-18051 on NVD →

W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name

high

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...

CVSS:
7.2
Affected:
up to 2.10.3
Fixed in:
2.10.4
Disclosed:
Aug 13, 2026

CVE-2026-18109 on NVD →

W3 Total Cache <= 2.10.2 - Unauthenticated Path Traversal

medium

The W3 Total Cache plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.10.2. This makes it possible for unauthenticated attackers to perform actions on files outside of the originally intended directory.

CVSS:
5.3
Affected:
up to 2.10.2
Fixed in:
2.10.3
Disclosed:
Jul 31, 2026

CVE-2026-66695 on NVD →

W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter

high

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requir...

CVSS:
7.5
Affected:
up to 2.9.4
Fixed in:
2.10.0
Disclosed:
Jul 10, 2026

CVE-2026-9282 on NVD →

W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary Code Execution

high

The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.4. This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
8.1
Affected:
up to 2.9.4
Fixed in:
2.10.0
Disclosed:
Jun 29, 2026

CVE-2026-57623 on NVD →

W3 Total Cache - Unauthenticated Security Token Exposure via User-Agent Header vulnerability

high

Unauthenticated Security Token Exposure via User-Agent Header vulnerability

CVSS:
7.5
Affected:
up to 2.9.3
Fixed in:
2.9.4
Disclosed:
Apr 2, 2026

W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header

high

The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains "W3 Total Cache", which causes raw mfunc/mclude dynamic fragmen...

CVSS:
7.5
Affected:
up to 2.9.3
Fixed in:
2.9.4
Disclosed:
Apr 1, 2026

CVE-2026-5032 on NVD →

W3 Total Cache <= 2.9.1 - Missing Authorization

medium

The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with author-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.9.1
Fixed in:
2.9.2
Disclosed:
Mar 12, 2026

CVE-2026-39595 on NVD →

W3 Total Cache <= 2.9.1 - Unauthenticated Arbitrary Code Execution

critical

The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 2.9.1
Fixed in:
2.9.2
Disclosed:
Feb 24, 2026

CVE-2026-27384 on NVD →

W3 Total Cache <= 2.8.12 - Unauthenticated Command Injection

high

The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.8.12 via _parse_dynamic_mfunc . This makes it possible for unauthenticated attackers to execute code on the server when comments are enabled and a post has been incorrectly injected with the mfunc tags...

CVSS:
8.1
Affected:
up to 2.8.12
Fixed in:
2.8.13
Disclosed:
Oct 27, 2025

CVE-2025-9501 on NVD →

W3 Total Cache [w3-total-cache] < 2.8.2

unknown

[en] The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example, the log file ma...

Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Jan 14, 2025

CVE-2024-12008 on NVD →

W3 Total Cache [w3-total-cache] < 2.8.2

unknown

[en] The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin exte...

Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Jan 14, 2025

CVE-2024-12006 on NVD →

W3 Total Cache [w3-total-cache] < 2.8.2

unknown

[en] The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain the plugin's n...

Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Jan 14, 2025

CVE-2024-12365 on NVD →

W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery

high

The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain the plugin's nonce...

CVSS:
8.5
Affected:
up to 2.8.1
Fixed in:
2.8.2
Disclosed:
Jan 13, 2025

CVE-2024-12365 on NVD →

W3 Total Cache <= 2.8.1 Information Exposure via Log Files

medium

The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example, the log file may con...

CVSS:
5.3
Affected:
up to 2.8.1
Fixed in:
2.8.2
Disclosed:
Jan 13, 2025

CVE-2024-12008 on NVD →

W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation

medium

The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin extension...

CVSS:
5.3
Affected:
up to 2.8.1
Fixed in:
2.8.2
Disclosed:
Jan 13, 2025

CVE-2024-12006 on NVD →

W3 Total Cache [w3-total-cache] < 2.7.6

unknown

[en] The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user acco...

Affected:
up to 2.7.6
Fixed in:
2.7.6
Disclosed:
Sep 24, 2024

CVE-2023-5359 on NVD →

W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext

low

The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account i...

CVSS:
3.7
Affected:
up to 2.7.5
Fixed in:
2.7.6
Disclosed:
Sep 23, 2024

CVE-2023-5359 on NVD →

W3 Total Cache [w3-total-cache] < 2.2.3

unknown

[en] Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` header. On making a request which responds with a redirect to a URI with a differ...

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Jun 27, 2022

CVE-2022-31090 on NVD →

Guzzle <= 6.5.7 and 7.0-7.4.4 - Information Exposure

high

Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` header. On making a request which responds with a redirect to a URI with a different o...

CVSS:
7.7
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Jun 20, 2022

CVE-2022-31090 on NVD →

W3 Total Cache [w3-total-cache] < 2.1.5

unknown

[en] The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without pr...

Affected:
up to 2.1.5
Fixed in:
2.1.5
Disclosed:
Jul 19, 2021

CVE-2021-24452 on NVD →

W3 Total Cache [w3-total-cache] < 2.1.4

unknown

[en] The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated...

Affected:
up to 2.1.4
Fixed in:
2.1.4
Disclosed:
Jul 19, 2021

CVE-2021-24436 on NVD →

W3 Total Cache [w3-total-cache] < 2.1.3

unknown

[en] The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Jul 12, 2021

CVE-2021-24427 on NVD →

W3 Total Cache <= 2.1.4 - Reflected Cross-Site Scripting via extension

high

The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper...

CVSS:
7.2
Affected:
0.5 – 2.1.4
Fixed in:
2.1.5
Disclosed:
Jun 28, 2021

CVE-2021-24452 on NVD →

W3 Total Cache <= 2.1.3 - Reflected Cross-Site Scripting via extension

medium

The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated admi...

CVSS:
6.1
Affected:
up to 2.1.4
Fixed in:
2.1.4
Disclosed:
Jun 28, 2021

CVE-2021-24436 on NVD →

W3 Total Cache <= 2.1.2 Authenticated (Admin+) Stored Cross-Site Scripting

medium

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several CDN settings in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject a...

CVSS:
4.8
Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Jun 16, 2021

CVE-2021-24427 on NVD →

W3 Total Cache 0.9.2.6-0.9.3 - File Read / Directory Traversal

high

The script pub/sns.php in the W3 Total Cache plugin (versions 0.9.2.6 through 0.9.3) allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.

CVSS:
7.5
Affected:
0.9.2.6 – 0.9.3
Fixed in:
0.9.4
Disclosed:
Dec 22, 2020

CVE-2019-6715 on NVD →

W3 Total Cache <= 0.9.2.4 - Sensitive Information Exposure

high

W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.

CVSS:
7.5
Affected:
up to 0.9.2.4
Fixed in:
0.9.2.5
Disclosed:
Sep 22, 2020

CVE-2012-6079 on NVD →

W3 Total Cache <= 0.9.2.4 - Password Hash Extraction

high

W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.

CVSS:
7.5
Affected:
up to 0.9.2.4
Fixed in:
0.9.2.5
Disclosed:
Sep 22, 2020

CVE-2012-6077 on NVD →

W3 Total Cache <= 0.9.2.4 - Insecure Cryptography to Sensitive Information Disclosure

high

W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.

CVSS:
7.5
Affected:
up to 0.9.2.4
Fixed in:
0.9.2.5
Disclosed:
Sep 22, 2020

CVE-2012-6078 on NVD →

W3 Total Cache [w3-total-cache] < 0.9.2.9

unknown

[en] WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability

Affected:
up to 0.9.2.9
Fixed in:
0.9.2.9
Disclosed:
Feb 12, 2020

CVE-2013-2010 on NVD →

W3 Total Cache [w3-total-cache] < 0.9.2.5

unknown

[en] W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.

Affected:
up to 0.9.2.5
Fixed in:
0.9.2.5
Disclosed:
Nov 22, 2019

CVE-2012-6079 on NVD →

W3 Total Cache [w3-total-cache] < 0.9.2.5

unknown

[en] W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.

Affected:
up to 0.9.2.5
Fixed in:
0.9.2.5
Disclosed:
Nov 22, 2019

CVE-2012-6077 on NVD →

W3 Total Cache [w3-total-cache] < 0.9.2.5

unknown

[en] W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.

Affected:
up to 0.9.2.5
Fixed in:
0.9.2.5
Disclosed:
Nov 22, 2019

CVE-2012-6078 on NVD →

W3 Total Cache <= 0.9.7.3 - Server Side Request Forgery

medium

The W3 Total Cache plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including 0.9.7.3, due to insufficient user input validation in the opcache_flush_file file.

CVSS:
5.4
Affected:
up to 0.9.7.3
Fixed in:
0.9.7.4
Disclosed:
May 22, 2019

W3 Total Cache [w3-total-cache] < 0.9.7.4

unknown

The W3 Total Cache plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including 0.9.7.3, due to insufficient user input validation in the opcache_flush_file file.

Affected:
up to 0.9.7.4
Fixed in:
0.9.7.4
Disclosed:
May 22, 2019

W3 Total Cache plugin <= 0.9.7.3 - Reflected Cross-Site Scripting

medium

The W3 Total Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation on the $command variable, which makes it possible for attackers to inject arbitrary web sites in victims browsers in versions up to, and including, 0.9.7.3.

CVSS:
6.1
Affected:
up to 0.9.7.3
Fixed in:
0.9.7.4
Disclosed:
May 7, 2019

W3 Total Cache <= 0.9.7.3 - Improper Input Validation via openssl_verify

medium

W3 Total Cache in versions 0.5 up to 0.9.7.3 does not sufficiently validate the "openssl_verify" result in "/services/MessageValidator/MessageValidator.php". A remote attacker can create a specially crafted certificate and bypass cryptographic checks.

CVSS:
4.3
Affected:
up to 0.9.7.3
Fixed in:
0.9.7.4
Disclosed:
May 7, 2019

W3 Total Cache [w3-total-cache] < 0.9.7.4

unknown

The W3 Total Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation on the $command variable, which makes it possible for attackers to inject arbitrary web sites in victims browsers in versions up to, and including, 0.9.7.3.

Affected:
up to 0.9.7.4
Fixed in:
0.9.7.4
Disclosed:
May 7, 2019

W3 Total Cache [w3-total-cache] < 0.9.7.4

unknown

W3 Total Cache in versions 0.5 up to 0.9.7.3 does not sufficiently validate the "openssl_verify" result in "/services/MessageValidator/MessageValidator.php". A remote attacker can create a specially crafted certificate and bypass cryptographic checks.

Affected:
up to 0.9.7.4
Fixed in:
0.9.7.4
Disclosed:
May 7, 2019

W3 Total Cache [w3-total-cache] < 0.9.7.4

unknown

Cross-Site Scripting (XSS) vulnerability found by Thomas Chauchefoin in WordPress W3 Total Cache plugin (versions <= 0.9.7.3).

Affected:
up to 0.9.7.4
Fixed in:
0.9.7.4
Disclosed:
May 7, 2019

W3 Total Cache [w3-total-cache] < 0.9.4

unknown

[en] pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.

Affected:
up to 0.9.4
Fixed in:
0.9.4
Disclosed:
Apr 1, 2019

CVE-2019-6715 on NVD →

W3 Total Cache <= 0.9.4.1 - Weak validation of Amazon SNS push messages

high

The W3 Total Cache plugin for WordPress is vulnerable to weak validation of Amazon SNS push messages in versions up to, and including, 0.9.4.1. This makes it possible for attackers to perform a variety of actions concerning the server's cache, such as performing a Denial of Service attack on the site.

CVSS:
7.2
Affected:
up to 0.9.4.1
Fixed in:
0.9.5
Disclosed:
Nov 10, 2016

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

The W3 Total Cache plugin for WordPress is vulnerable to weak validation of Amazon SNS push messages in versions up to, and including, 0.9.4.1. This makes it possible for attackers to perform a variety of actions concerning the server's cache, such as performing a Denial of Service attack on the site.

Affected:
up to 0.9.5
Fixed in:
0.9.5
Disclosed:
Nov 10, 2016

W3 Total Cache <= 0.9.4 - Server-Side Request Forgery leading to Host Information Disclosure

high

The W3 Total Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 0.9.4. This is due to a minify function incorrectly restricting path input. This makes it possible for attackers to access restricted resources on private networks by using a vulnerable installation as...

CVSS:
8.6
Affected:
up to 0.9.4
Fixed in:
0.9.5
Disclosed:
Oct 31, 2016

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

The W3 Total Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 0.9.4. This is due to a minify function incorrectly restricting path input. This makes it possible for attackers to access restricted resources on private networks by using a vulnerable installation as...

Affected:
up to 0.9.5
Fixed in:
0.9.5
Disclosed:
Oct 31, 2016

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

This plugin is prone to an authenticated arbitrary file upload vulnerability. Update the plugin.

Affected:
up to 0.9.5
Fixed in:
0.9.5
Disclosed:
Sep 27, 2016

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

This plugin is prone to unauthenticated security token bypass vulnerability. Update the plugin.

Affected:
up to 0.9.5
Fixed in:
0.9.5
Disclosed:
Sep 27, 2016

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

This plugin is prone to an authenticated arbitrary PHP code execution vulnerability. Update the plugin.

Affected:
up to 0.9.5
Fixed in:
0.9.5
Disclosed:
Sep 27, 2016

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

This plugin is prone to authenticated arbitrary file download vulnerability. Update the plugin.

Affected:
up to 0.9.5
Fixed in:
0.9.5
Disclosed:
Sep 27, 2016

W3 Total Cache <= 0.9.4.1 - Arbitrary File Upload

high

The W3 Total Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 0.9.4.1. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVSS:
8.8
Affected:
up to 0.9.4.1
Fixed in:
0.9.5
Disclosed:
Sep 26, 2016

W3 Total Cache <= 0.9.4.1 - Arbitrary Code Execution via settings import

high

The W3 Total Cache plugin for WordPress is vulnerable to Authenticated Arbitrary Code Execution via settings import in versions up to, and including, 0.9.4.1. This makes it possible for authenticated attackers to inject and execute arbitrary code.

CVSS:
7.2
Affected:
up to 0.9.4.1
Fixed in:
0.9.5
Disclosed:
Sep 26, 2016

W3 Total Cache <= 0.9.4.1 - Authenticated Arbitrary File Download

medium

The W3 Total Cache plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 0.9.4.1 This can allow an administrator attacker to extract sensitive data from wp-config.php that could be used to fully take over the site.

CVSS:
4.9
Affected:
up to 0.9.4.1
Fixed in:
0.9.5
Disclosed:
Sep 26, 2016

W3 Total Cache <= 0.9.4.1 - Security Token Bypass via Type Juggling

low

The W3 Total Cache plugin for WordPress is vulnerable to authorization bypass due to the use of loose comparison on the nonce value in the /pub/apc.php file. This affects versions up to, and including, 0.9.4.1. This makes it possible for attackers to bypass nonce protections if a valid nonce starts with 0e. In the rig...

CVSS:
3.7
Affected:
up to 0.9.4.1
Fixed in:
0.9.5
Disclosed:
Sep 26, 2016

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 0.9.5
Fixed in:
0.9.5
Disclosed:
Sep 26, 2016

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

The W3 Total Cache plugin for WordPress is vulnerable to Authenticated Arbitrary Code Execution via settings import in versions up to, and including, 0.9.4.1. This makes it possible for authenticated attackers to inject and execute arbitrary code.

Affected:
up to 0.9.5
Fixed in:
0.9.5
Disclosed:
Sep 26, 2016

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

The W3 Total Cache plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 0.9.4.1 This can allow an administrator attacker to extract sensitive data from wp-config.php that could be used to fully take over the site.

Affected:
up to 0.9.5
Fixed in:
0.9.5
Disclosed:
Sep 26, 2016

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

The W3 Total Cache plugin for WordPress is vulnerable to authorization bypass due to the use of loose comparison on the nonce value in the /pub/apc.php file. This affects versions up to, and including, 0.9.4.1. This makes it possible for attackers to bypass nonce protections if a valid nonce starts with 0e. In the rig...

Affected:
up to 0.9.5
Fixed in:
0.9.5
Disclosed:
Sep 26, 2016

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

The W3 Total Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 0.9.4.1. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Affected:
up to 0.9.5
Fixed in:
0.9.5
Disclosed:
Sep 26, 2016

W3 Total Cache <= 0.9.4.1 - Cross-Site Scripting via request_id

medium

The W3 Total Cache plugin plugin for WordPress is vulnerable to Cross-Site Scripting via the 'request_id' parameter in versions up to, and including, 0.9.4.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browse...

CVSS:
6.1
Affected:
up to 0.9.4.1
Fixed in:
0.9.5
Disclosed:
Jul 29, 2016

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

The W3 Total Cache plugin plugin for WordPress is vulnerable to Cross-Site Scripting via the 'request_id' parameter in versions up to, and including, 0.9.4.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browse...

Affected:
up to 0.9.5
Fixed in:
0.9.5
Disclosed:
Jul 29, 2016

W3 Total Cache [w3-total-cache] < 0.9.4.1

unknown

This plugin is prone to edge mode enabling cross site request forgery vulnerability. Update the plugin.

Affected:
up to 0.9.4.1
Fixed in:
0.9.4.1
Disclosed:
May 15, 2015

W3 Total Cache [w3-total-cache] < 0.9.4.1

unknown

[en] The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] p...

Affected:
up to 0.9.4.1
Fixed in:
0.9.4.1
Disclosed:
Dec 24, 2014

CVE-2014-9414 on NVD →

W3 Total Cache [w3-total-cache] < 0.9.4.1

unknown

[en] Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the "Cache key" in the HTML-Comments, as demonstrated by the PATH_INFO to the default URI.

Affected:
up to 0.9.4.1
Fixed in:
0.9.4.1
Disclosed:
Dec 19, 2014

CVE-2014-8724 on NVD →

W3 Total Cache <= 0.9.4 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the "Cache key" in the HTML-Comments, as demonstrated by the PATH_INFO to the default URI.

CVSS:
5.4
Affected:
up to 0.9.4
Fixed in:
0.9.4.1
Disclosed:
Dec 16, 2014

CVE-2014-8724 on NVD →

W3 Total Cache <= 0.9.4 - Cross-Site Request Forgery

medium

The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parame...

CVSS:
4.3
Affected:
up to 0.9.4
Fixed in:
0.9.4.1
Disclosed:
Dec 10, 2014

CVE-2014-9414 on NVD →

W3 Total Cache <= 0.9.4 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting

high

The W3 Total Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.9.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page via forged request granted they can trick...

CVSS:
8.8
Affected:
up to 0.9.4
Fixed in:
0.9.4.1
Disclosed:
Sep 8, 2014

W3 Total Cache [w3-total-cache] < 0.9.4.1

unknown

The W3 Total Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.9.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page via forged request granted they can trick...

Affected:
up to 0.9.4.1
Fixed in:
0.9.4.1
Disclosed:
Sep 8, 2014

W3 Total Cache <= 0.9.2.8 - Remote Code Execution

critical

WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability

CVSS:
9.8
Affected:
up to 0.9.2.8
Fixed in:
0.9.2.9
Disclosed:
Aug 1, 2014

CVE-2013-2010 on NVD →

W3 Total Cache [w3-total-cache] < 0.9.2.9

unknown

W3 Total Cache plugin is prone to a PHP code execution vulnerability because of the handling of certain macros such as "mfunc" that allows arbitrary PHP code injection. Update the WordPress W3 Total Cache plugin to the latest available version (at least 0.9.2.9).

Affected:
up to 0.9.2.9
Fixed in:
0.9.2.9
Disclosed:
May 1, 2013

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

The W3 Total Cache WordPress plugin was affected by a Weak Validation of Amazon SNS Push Messages security vulnerability.

Affected:
up to 0.9.5
Fixed in:
0.9.5

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

The W3 Total Cache WordPress plugin was affected by an Information Disclosure Race Condition security vulnerability.

Affected:
up to 0.9.5
Fixed in:
0.9.5

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

The W3 Total Cache WordPress plugin was affected by an Unauthenticated Server Side Request Forgery (SSRF) security vulnerability.

Affected:
up to 0.9.5
Fixed in:
0.9.5

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

When you&#039;re creating a support ticket in the plugin page, you can add one or more of your your template themes. Then this file will be send to the author to help him resolving the issue. Now you select one, you send the form and same as for the files before, you will send it to the author to help him to fix...

Affected:
up to 0.9.5
Fixed in:
0.9.5

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

When you&#039;re creating a support ticket in the plugin page, you can add one or more of your files from your computer. Then this file will be send to the author to help him resolving the issue. When we look at the code, W3TC is doing that: ********** /** * Attach other files */...

Affected:
up to 0.9.5
Fixed in:
0.9.5

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

This one is so mush easy to exploit using the import settings feature, this is what W3TC will do one your file is uploaded: ********** /** * Imports config content * * @param string $filename * @return boolean */ function import($filename) { if (file_exists($filename) &...

Affected:
up to 0.9.5
Fixed in:
0.9.5

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

The /pub/apc.php file is used to empty the OPCache/APC. The script seems protected by a nonce (aka security token): *********** $nonce = W3_Request::get_string(&#039;nonce&#039;); $uri = $_SERVER[&#039;REQUEST_URI&#039;]; if (wp_hash($uri) == $nonce) { ************ But the flaw stays in the == operator which...

Affected:
up to 0.9.5
Fixed in:
0.9.5

W3 Total Cache [w3-total-cache] < 0.9.5

unknown

The W3 Total Cache WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 0.9.5
Fixed in:
0.9.5

W3 Total Cache [w3-total-cache] < 0.9.4.1

unknown

The W3 Total Cache WordPress plugin was affected by an Edge Mode Enabling CSRF security vulnerability.

Affected:
up to 0.9.4.1
Fixed in:
0.9.4.1

W3 Total Cache [w3-total-cache] < 0.9.7.4

unknown

The implementation of `opcache_flush_file` calls `file_exists` with a parameter fully controlled by the user.

Affected:
up to 0.9.7.4
Fixed in:
0.9.7.4

W3 Total Cache [w3-total-cache] < 0.9.7.4

unknown

The W3 Total Cache WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 0.9.7.4
Fixed in:
0.9.7.4

W3 Total Cache [w3-total-cache] < 0.9.7.4

unknown

The return value of `openssl_verify` is not properly validated, which allows to bypass the cryptographic check.

Affected:
up to 0.9.7.4
Fixed in:
0.9.7.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database