Extension WordPress
Vulnérabilités W3 Total Cache
Cette page rassemble les failles publiées pour W3 Total Cache, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de W3 Total Cache
32 fiches
W3 Total Cache <= 2.9.4 – Unauthenticated Arbitrary File Read via 'f_array[]' Parameter
The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files…
*-2.9.4
2.10.0
10/07/2026
W3 Total Cache <= 2.9.4 – Unauthenticated Arbitrary Code Execution
The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.4. This makes it possible for unauthenticated attackers to execute code on the server.
*-2.9.4
2.10.0
29/06/2026
W3 Total Cache <= 2.9.3 – Unauthenticated Security Token Exposure via User-Agent Header
The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent…
*-2.9.3
2.9.4
01/04/2026
W3 Total Cache <= 2.9.1 – Missing Authorization
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with author-level access…
*-2.9.1
2.9.2
12/03/2026
W3 Total Cache <= 2.9.1 – Unauthenticated Arbitrary Code Execution
The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to execute code on the server.
*-2.9.1
2.9.2
24/02/2026
W3 Total Cache <= 2.8.12 – Unauthenticated Command Injection
The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.8.12 via _parse_dynamic_mfunc . This makes it possible for unauthenticated attackers to execute code on the server when…
*-2.8.12
2.8.13
27/10/2025
W3 Total Cache <= 2.8.1 – Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated…
*-2.8.1
2.8.2
13/01/2025
W3 Total Cache <= 2.8.1 Information Exposure via Log Files
The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive…
*-2.8.1
2.8.2
13/01/2025
W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers…
*-2.8.1
2.8.2
13/01/2025
W3 Total Cache <= 2.7.5 – Sensitive Credentials Stored in Plaintext
The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated…
*-2.7.5
2.7.6
23/09/2024
Guzzle <= 6.5.7 and 7.0-7.4.4 – Information Exposure
Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` header. On making a request…
*-2.2.2
2.2.3
20/06/2022
W3 Total Cache <= 2.1.4 – Reflected Cross-Site Scripting via extension
The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as…
0.5-2.1.4
2.1.5
28/06/2021
W3 Total Cache <= 2.1.3 – Reflected Cross-Site Scripting via extension
The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could…
[*, 2.1.4)
2.1.4
28/06/2021
W3 Total Cache <= 2.1.2 Authenticated (Admin+) Stored Cross-Site Scripting
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several CDN settings in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
[*, 2.1.3)
2.1.3
16/06/2021
W3 Total Cache 0.9.2.6-0.9.3 – File Read / Directory Traversal
The script pub/sns.php in the W3 Total Cache plugin (versions 0.9.2.6 through 0.9.3) allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.
0.9.2.6-0.9.3
0.9.4
22/12/2020
W3 Total Cache <= 0.9.2.4 – Insecure Cryptography to Sensitive Information Disclosure
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
*-0.9.2.4
0.9.2.5
22/09/2020
W3 Total Cache <= 0.9.2.4 – Sensitive Information Exposure
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.
*-0.9.2.4
0.9.2.5
22/09/2020
W3 Total Cache <= 0.9.2.4 – Password Hash Extraction
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
*-0.9.2.4
0.9.2.5
22/09/2020
W3 Total Cache <= 0.9.7.3 – Server Side Request Forgery
The W3 Total Cache plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including 0.9.7.3, due to insufficient user input validation in the opcache_flush_file file.
*-0.9.7.3
0.9.7.4
22/05/2019
W3 Total Cache plugin <= 0.9.7.3 – Reflected Cross-Site Scripting
The W3 Total Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation on the $command variable, which makes it possible for attackers to inject arbitrary web sites in victims browsers in versions…
*-0.9.7.3
0.9.7.4
07/05/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.