CVE Database /
CVE-2026-18051
CVE
CVE-2026-18051 — W3 Total Cache [w3-total-cache] < 2.10.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-18051
|
W3 Total Cache [w3-total-cache] < 2.10.5 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Unknown
|
< 2.10.5
|
2.10.5 |
2026-08-19 |
—
|
CVE-2026-18051
A vulnerability exists in the W3 Total Cache WordPress plugin prior to version 2.10.5, where it fails to properly verify the request path used to generate cache file names, enabling an attacker to write a file to any directory on the server, including those outside the web root, and potentially overwrite critical files such as .htaccess files on Apache servers, compromising the site's functionality and security.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings