Executive brief
W3 Total Cache is a popular WordPress plugin used to improve website performance and speed. A security flaw in versions 2.9.4 and earlier allows an unauthorized attacker to run malicious code on the web server. This could lead to a complete takeover of the website, theft of customer data, or the installation of ransomware.
Technical details
W3 Total Cache is vulnerable to unauthenticated arbitrary code execution (ACE) in versions up to and including 2.9.4. The vulnerability is classified under CWE-1284 (Improper Validation of Specified Quantity in Input), suggesting that insufficient validation of user-supplied input allows for code injection or execution. An attacker can exploit this over the network without any prior authentication or user interaction. Successful exploitation grants the attacker the ability to execute arbitrary commands with the privileges of the web server process. The issue has been addressed in version 2.10.0.
Affected products
- BoldGrid W3 Total Cache <= 2.9.4
Timeline
- 2026-04-17: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-06-29: advisory: Patchstack advisory published
- 2026-07-02: advisory: NVD published CVE-2026-57623
- patched: Fixed in version 2.10.0