← back
CVE-2026-18051criticalCWE-22

W3 Total Cache < 2.10.5 - Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page Cache Key

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 10epss 0.4%
exploitation probability
0.4%top 63% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Affected products
Unknown · W3 Total Cache
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.