Executive brief
W3 Total Cache is a widely-used WordPress plugin that optimizes website performance through caching and asset management. An unauthenticated path traversal vulnerability in versions 2.10.2 and earlier allows attackers to access sensitive files stored outside the website's intended directory, potentially exposing database backups, configuration files, and other private data without requiring login credentials.
Technical details
The vulnerability is a path traversal flaw (CWE-22) affecting the W3 Total Cache WordPress plugin up to version 2.10.2. It requires no authentication and is exploitable over the network, allowing attackers to escape the web root directory and read arbitrary files on the server filesystem. An attacker can leverage directory traversal sequences to navigate to sensitive locations and retrieve private configuration, backup, or credential files. The vulnerability is classified as unauthenticated access control bypass and has been patched in version 2.10.3.
Affected products
- BoldGrid W3 Total Cache <=2.10.2
Timeline
- 2026-07-31: disclosed
- 2026-07-31: patched: patch available in version 2.10.3