Plugin Vulnerability Hub
Plugin 29 known issues Latest disclosed Apr 01, 2026

W3 Total Cache Vulnerabilities

Review known vulnerability records for the WordPress plugin W3 Total Cache (`w3-total-cache`), including severity, CVE references, affected versions, and patch status.

Known Records
29
High or Critical
16
Linked CVEs
18
Last Updated
Apr 01, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for W3 Total Cache so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
29 records include a published patch path.
Severity Mix
2 critical and 14 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for W3 Total Cache

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-5032
W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header

The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains "W3 Total Cache", which...

Published
Apr 01, 2026
Patched Release
2.9.4
Affected Versions
Versions up to 2.9.3
Next Step
Update to 2.9.4 or newer if supported.
Plugin Critical Patched: Yes CVE-2026-27384
W3 Total Cache <= 2.9.1 - Unauthenticated Arbitrary Code Execution

The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to execute code on the server.

Published
Feb 24, 2026
Patched Release
2.9.2
Affected Versions
Versions up to 2.9.1
Next Step
Update to 2.9.2 or newer if supported.
Plugin High Patched: Yes CVE-2025-9501
W3 Total Cache <= 2.8.12 - Unauthenticated Command Injection

The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.8.12 via _parse_dynamic_mfunc . This makes it possible for unauthenticated attackers to execute code on the server when comments are enabled and a post has been...

Published
Oct 27, 2025
Patched Release
2.8.13
Affected Versions
Versions up to 2.8.12
Next Step
Update to 2.8.13 or newer if supported.
Plugin High Patched: Yes CVE-2024-12365
W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery

The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access...

Published
Jan 13, 2025
Patched Release
2.8.2
Affected Versions
Versions up to 2.8.1
Next Step
Update to 2.8.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-12008
W3 Total Cache <= 2.8.1 Information Exposure via Log Files

The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log...

Published
Jan 13, 2025
Patched Release
2.8.2
Affected Versions
Versions up to 2.8.1
Next Step
Update to 2.8.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-12006
W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation

The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as...

Published
Jan 13, 2025
Patched Release
2.8.2
Affected Versions
Versions up to 2.8.1
Next Step
Update to 2.8.2 or newer if supported.
Plugin Low Patched: Yes CVE-2023-5359
W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext

The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total...

Published
Sep 23, 2024
Patched Release
2.7.6
Affected Versions
Versions up to 2.7.5
Next Step
Update to 2.7.6 or newer if supported.
Plugin High Patched: Yes CVE-2022-31090
Guzzle <= 6.5.7 and 7.0-7.4.4 - Information Exposure

Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` header. On making a request which responds wit...

Published
Jun 20, 2022
Patched Release
2.2.3
Affected Versions
Versions up to 2.2.2
Next Step
Update to 2.2.3 or newer if supported.
Plugin High Patched: Yes CVE-2021-24452
W3 Total Cache <= 2.1.4 - Reflected Cross-Site Scripting via extension

The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output...

Published
Jun 28, 2021
Patched Release
2.1.5
Affected Versions
0.5 through 2.1.4
Next Step
Update to 2.1.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-24436
W3 Total Cache <= 2.1.3 - Reflected Cross-Site Scripting via extension

The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker...

Published
Jun 28, 2021
Patched Release
2.1.4
Affected Versions
Versions before 2.1.4
Next Step
Update to 2.1.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-24427
W3 Total Cache <= 2.1.2 Authenticated (Admin+) Stored Cross-Site Scripting

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several CDN settings in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative...

Published
Jun 16, 2021
Patched Release
2.1.3
Affected Versions
Versions before 2.1.3
Next Step
Update to 2.1.3 or newer if supported.
Plugin High Patched: Yes CVE-2019-6715
W3 Total Cache 0.9.2.6-0.9.3 - File Read / Directory Traversal

The script pub/sns.php in the W3 Total Cache plugin (versions 0.9.2.6 through 0.9.3) allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.

Published
Dec 22, 2020
Patched Release
0.9.4
Affected Versions
0.9.2.6 through 0.9.3
Next Step
Update to 0.9.4 or newer if supported.