PLUGIN SECURITY
Is W3 Total Cache safe?
Search Engine (SEO) & Performance Optimization (WPO) via caching. Integrated caching: CDN, Page, Minify, Object, Fragment, Database support.
What this plugin does
- Slug:
w3-total-cache - Author: BoldGrid
- 900000+ active installs
- 88/100 rating (5420 reviews on wordpress.org)
- 66051733 all-time downloads
- On WordPress.org since 2009-07-29
cachingcdnOptimizepagespeedperformance
Maintenance status
- Latest known version: 2.10.4
- Last updated: 2026-08-18 6:58pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
Known vulnerabilities
22 known CVEs on file for W3 Total Cache.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-18051 | W3 Total Cache [w3-total-cache] < 2.10.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Unknown | < 2.10.5 | 2.10.5 | 2026-08-19 | ⚠ update needed |
| CVE-2026-18109 | W3 Total Cache [w3-total-cache] < 2.10.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.2 | < 2.10.4 | 2.10.4 | 2026-08-13 | ✓ fixed in latest |
| CVE-2026-66695 | W3 Total Cache [w3-total-cache] < 2.10.3 | Path Traversal: '.../...//' | Medium 6.5 | < 2.10.3 | 2.10.3 | 2026-07-31 | ✓ fixed in latest |
| CVE-2026-9282 | W3 Total Cache [w3-total-cache] < 2.10.0 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.5 | < 2.10.0 | 2.10.0 | 2026-07-10 | ✓ fixed in latest |
| CVE-2026-57623 | W3 Total Cache [w3-total-cache] < 2.10.0 | Improper Validation of Specified Quantity in Input | Critical 9.0 | < 2.10.0 | 2.10.0 | 2026-06-29 | ✓ fixed in latest |
| CVE-2026-39595 | W3 Total Cache [w3-total-cache] < 2.9.2 | Missing Authorization | Medium 4.7 | < 2.9.2 | 2.9.2 | 2026-03-12 | ✓ fixed in latest |
| CVE-2026-27384 | W3 Total Cache [w3-total-cache] < 2.9.2 | Improper Validation of Specified Quantity in Input | Critical 9.0 | < 2.9.2 | 2.9.2 | 2026-02-24 | ✓ fixed in latest |
| CVE-2024-12008 | W3 Total Cache [w3-total-cache] < 2.8.2 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 2.8.2 | 2.8.2 | 2025-01-13 | ✓ fixed in latest |
+ 47 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-12006 | W3 Total Cache [w3-total-cache] < 2.8.2 | Missing Authorization | Medium 5.3 | < 2.8.2 | 2.8.2 | 2025-01-13 | ✓ fixed in latest |
| CVE-2024-12365 | W3 Total Cache [w3-total-cache] < 2.8.2 | Missing Authorization | High 8.5 | < 2.8.2 | 2.8.2 | 2025-01-13 | ✓ fixed in latest |
| CVE-2023-5359 | W3 Total Cache [w3-total-cache] < 2.7.6 | Exposure of Sensitive Information to an Unauthorized Actor | High 7.5 | < 2.7.6 | 2.7.6 | 2024-09-23 | ✓ fixed in latest |
| CVE-2022-31090 | W3 Total Cache [w3-total-cache] < 2.2.3 | Exposure of Sensitive Information to an Unauthorized Actor | High 7.7 | < 2.2.3 | 2.2.3 | 2022-06-20 | ✓ fixed in latest |
| CVE-2021-24452 | W3 Total Cache [w3-total-cache] < 2.1.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.1.5 | 2.1.5 | 2021-06-28 | ✓ fixed in latest |
| CVE-2021-24436 | W3 Total Cache [w3-total-cache] < 2.1.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.1.4 | 2.1.4 | 2021-06-28 | ✓ fixed in latest |
| CVE-2021-24427 | W3 Total Cache [w3-total-cache] < 2.1.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 2.1.3 | 2.1.3 | 2021-04-25 | ✓ fixed in latest |
| CVE-2012-6078 | W3 Total Cache [w3-total-cache] < 0.9.2.5 | Exposure of Sensitive Information to an Unauthorized Actor | High 7.5 | < 0.9.2.5 | 0.9.2.5 | 2019-11-22 | ✓ fixed in latest |
| CVE-2012-6077 | W3 Total Cache [w3-total-cache] < 0.9.2.5 | Exposure of Sensitive Information to an Unauthorized Actor | High 7.5 | < 0.9.2.5 | 0.9.2.5 | 2019-11-22 | ✓ fixed in latest |
| CVE-2012-6079 | W3 Total Cache [w3-total-cache] < 0.9.2.5 | Exposure of Sensitive Information to an Unauthorized Actor | High 7.5 | < 0.9.2.5 | 0.9.2.5 | 2019-11-22 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.7.4 | — | Unknown | < 0.9.7.4 | 0.9.7.4 | 2019-05-22 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.7.4 | — | Unknown | < 0.9.7.4 | 0.9.7.4 | 2019-05-07 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.7.4 | — | Unknown | < 0.9.7.4 | 0.9.7.4 | 2019-05-07 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.7.4 | — | Unknown | < 0.9.7.4 | 0.9.7.4 | 2019-05-07 | ✓ fixed in latest |
| CVE-2019-6715 | W3 Total Cache [w3-total-cache] < 0.9.4 | — | High 7.5 | < 0.9.4 | 0.9.4 | 2019-04-01 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | 2016-11-10 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | 2016-10-31 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | 2016-09-27 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | 2016-09-27 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | 2016-09-27 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | 2016-09-27 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | 2016-09-26 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | 2016-09-26 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | 2016-09-26 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | 2016-09-26 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | 2016-09-26 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | 2016-07-29 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.4.1 | — | Unknown | < 0.9.4.1 | 0.9.4.1 | 2015-05-15 | ✓ fixed in latest |
| CVE-2014-8724 | W3 Total Cache [w3-total-cache] < 0.9.4.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 0.9.4.1 | 0.9.4.1 | 2014-11-10 | ✓ fixed in latest |
| CVE-2014-9414 | W3 Total Cache [w3-total-cache] < 0.9.4.1 | Cross-Site Request Forgery (CSRF) | Unknown | < 0.9.4.1 | 0.9.4.1 | 2014-09-08 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.4.1 | — | Unknown | < 0.9.4.1 | 0.9.4.1 | 2014-09-08 | ✓ fixed in latest |
| CVE-2013-2010 | W3 Total Cache [w3-total-cache] < 0.9.2.9 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | Critical 9.8 | < 0.9.2.9 | 0.9.2.9 | 2014-08-01 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.2.9 | — | Unknown | < 0.9.2.9 | 0.9.2.9 | 2013-05-01 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 2.9.4 | — | Unknown | < 2.9.4 | 2.9.4 | 0000-00-00 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 2.8.13 | — | Unknown | < 2.8.13 | 2.8.13 | 0000-00-00 | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.7.4 | — | Unknown | < 0.9.7.4 | 0.9.7.4 | — | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.7.4 | — | Unknown | < 0.9.7.4 | 0.9.7.4 | — | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.7.4 | — | Unknown | < 0.9.7.4 | 0.9.7.4 | — | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | — | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | — | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | — | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | — | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | — | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | — | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | — | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.5 | — | Unknown | < 0.9.5 | 0.9.5 | — | ✓ fixed in latest |
| — | W3 Total Cache [w3-total-cache] < 0.9.4.1 | — | Unknown | < 0.9.4.1 | 0.9.4.1 | — | ✓ fixed in latest |
How to fix it
Keep W3 Total Cache updated — 2.10.4 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- LiteSpeed Cache — 7000000+ active installs — 96/100 (2764) — max PHP 8.4
- WP Super Cache — 1000000+ active installs — 86/100 (1345) — max PHP 8.4
- Speed Optimizer – The All-In-One Performance-Boosting Plugin — 1000000+ active installs — 84/100 (639) — max PHP 8.4
- WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance — 1000000+ active installs — 96/100 (2606) — max PHP 8.4
- SpeedyCache – Cache, Optimization, Performance — 600000+ active installs — 88/100 (30) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.