Junglewise Threat Intelligence

CVE-2026-39595: BoldGrid W3 Total Cache broken access control

CVE-2026-39595 · Severity: medium · CVSS 4.7 · Published 2026-06-17

Technologies: BoldGrid W3 Total Cache. Vendors: BoldGrid.

Executive brief

W3 Total Cache is a popular WordPress plugin used to improve website performance and speed through caching. A security flaw in versions 2.9.1 and earlier allows users with 'Author' level permissions to perform actions they should not be authorized to access. While this requires an internal account with elevated privileges, it could lead to unauthorized changes to site configuration or minor data exposure.

Technical details

A broken access control vulnerability (CWE-862: Missing Authorization) exists in the W3 Total Cache plugin for WordPress in versions up to and including 2.9.1. The flaw stems from insufficient authorization checks on certain functions, allowing a remote attacker with Author-level privileges (PR:H) to execute actions typically reserved for higher-privileged roles. An attacker can exploit this over the network without user interaction to potentially modify plugin settings or access restricted information. The issue is addressed in version 2.9.2.

Affected products

  • BoldGrid W3 Total Cache <= 2.9.1

Timeline

  • 2026-02-10: other: Reported by Muhammad Sharief
  • 2026-03-12: advisory: Initial advisory published by Patchstack
  • 2026-06-17: disclosed: CVE published to NVD
  • 2026-03-12: patched: Patch released in version 2.9.2

References

Related threats