CVE-2026-57623
The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.4. This makes it possible for unauthenticated attackers to execute code on the server.
Source: Wordfence
CVE · Critical
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-57623 | W3 Total Cache [w3-total-cache] < 2.10.0 | Improper Validation of Specified Quantity in Input | Critical 9.0 | < 2.10.0 | 2.10.0 | 2026-06-29 | — |
The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.4. This makes it possible for unauthenticated attackers to execute code on the server.
Source: Wordfence
No signup, no credit card — enter your URL and get a security report in seconds.