W3 Total Cache
Vendor:
First CVE: Dec 19, 2014 · Active for 11 years
19
Total CVEs
More Total CVEs than 93% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact W3 Total Cache over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2014
11 years ago
Most Recent CVE
Jul 11, 2026
15 days ago
CVE Severity & Scoring
W3 Total Cache19 CVEs
37%
47%
16%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (89.5%)
Unknown2 (10.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (78.9%)
High2 (10.5%)
Unknown2 (10.5%)
User Interaction
None14 (73.7%)
Unknown2 (10.5%)
Required3 (15.8%)
Privileges Required
Low1 (5.3%)
High2 (10.5%)
None14 (73.7%)
Unknown2 (10.5%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2010CRITICAL WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability | Feb 12, 2020 | 9.8 | 88 | NO | YES |
CVE-2026-9282HIGH The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for u | Jul 11, 2026 | 7.5 | 49 | NO | YES |
CVE-2019-6715HIGH pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data | Apr 1, 2019 | 7.5 | 46 | NO | YES |
CVE-2026-57623CRITICAL Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. | Jul 2, 2026 | 9.0 | 37 | NO | NO |
CVE-2024-12008HIGH The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it | Jan 14, 2025 | 7.5 | 32 | NO | YES |
CVE-2021-24452MEDIUM The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the | Jul 19, 2021 | 6.1 | 31 | NO | YES |
CVE-2021-24436MEDIUM The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions | Jul 19, 2021 | 6.1 | 30 | NO | YES |
CVE-2026-27384CRITICAL Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issu | Mar 5, 2026 | 9.0 | 29 | NO | NO |
CVE-2024-12365HIGH The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and | Jan 14, 2025 | 8.5 | 28 | NO | NO |
CVE-2026-5032HIGH The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buf | Apr 2, 2026 | 7.5 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.3% of CVEs· 97th percentile
Nuclei
5 CVEs
26.3% of CVEs· 98th percentile
ExploitDB
1 CVE
5.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For W3 Total Cache
Top CWEs
Versions
No cataloged versions.