CVE

CVE-2026-18051 — W3 Total Cache [w3-total-cache] < 2.10.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-18051 W3 Total Cache [w3-total-cache] < 2.10.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 2.10.5 2.10.5 2026-08-19

CVE-2026-18051

A vulnerability exists in the W3 Total Cache WordPress plugin prior to version 2.10.5, where it fails to properly verify the request path used to generate cache file names, enabling an attacker to write a file to any directory on the server, including those outside the web root, and potentially overwrite critical files such as .htaccess files on Apache servers, compromising the site's functionality and security.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.