Threat Advisory

Critical W3 Total Cache Vulnerability Facilitates Unverified Permission Settings Alteration

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-18051, with a CVSS score of 10.0, is a critical vulnerability affecting the W3 Total Cache WordPress plugin. The flaw allows unauthenticated attackers to write arbitrary files through a path traversal weakness, potentially overwriting .htaccess files, breaking website functionality, or removing security hardening rules. Due to the lack of authentication requirements and user interaction, the vulnerability can be exploited at scale. The business impact is significant, as W3 Total Cache is one of the most widely used WordPress caching plugins for improving website performance, SEO, and Core Web Vitals. Exploitation could allow attackers to disrupt websites or weaken existing security controls, resulting in severe consequences if left unpatched. Users are advised to update W3 Total Cache to the latest patched version to mitigate this vulnerability.

RECOMMENDATION:

We recommend you to update W3 Total Cache to version 2.10.5 or later.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-18051, with a CVSS score of 10.0, is a critical vulnerability affecting the W3 Total Cache WordPress plugin. The flaw allows unauthenticated attackers to write arbitrary files through a path traversal weakness, potentially overwriting .htaccess files, breaking website functionality, or removing security hardening rules. Due to the lack of authentication requirements and user interaction, the vulnerability can be exploited at scale. The business impact is significant, as W3 Total Cache is one of the most widely used WordPress caching plugins for improving website performance, SEO, and Core Web Vitals. Exploitation could allow attackers to disrupt websites or weaken existing security controls, resulting in severe consequences if left unpatched. Users are advised to update W3 Total Cache to the latest patched version to mitigate this vulnerability.

RECOMMENDATION:

We recommend you to update W3 Total Cache to version 2.10.5 or later.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu