W3 total cache
This hub aggregates every CVE we track for W3 total cache, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
21
CVEs tracked
4
Critical
7
High
0
In CISA KEV
Severity distribution
MEDIUM9HIGH7CRITICAL4LOW1
Monthly trend
1
0
0
0
3
0
0
0
0
0
0
0
0
0
1
0
0
0
1
1
0
1
2
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting W3 total cache.
- CVE-2026-66695WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability6.5
- CVE-2026-9282W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter7.5
- CVE-2026-57623WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerability9.0
- CVE-2026-39595WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerability4.7
- CVE-2026-5032W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header7.5
- CVE-2026-27384WordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerability9.0
- CVE-2025-9501W3 Total Cache < 2.8.13 - Unauthenticated Command Injection9.0
- CVE-2024-12008W3 Total Cache <= 2.8.1 Information Exposure via Log Files5.3
- CVE-2024-12006W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation5.3
- CVE-2024-12365W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery8.5
- CVE-2023-5359W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext3.7
- CVE-2021-24452W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context)6.1
- CVE-2021-24436W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context)6.1
- CVE-2021-24427W3 Total Cache < 2.1.3 - Authenticated Stored XSS4.8
- CVE-2013-2010WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability9.8
Product normalization is registry-driven with AI assist and human review. How it works