THE page reports on a critical vulnerability identified as CVE-2026-18051 in the W3 Total Cache plugin, affecting WordPress sites running versions before 2.10.5. This vulnerability allows unauthenticated attackers to write files anywhere on the server, including the ability to overwrite .htaccess files, posing serious security risks. The flaw has a perfect CVSS score of 10, indicating its severe impact. Users are advised to update to version 2.10.5 immediately, as no confirmed exploitation has been reported yet. Detailed mitigation steps include checking .htaccess files for unauthorized changes after patching.
CVE-2026-18051 (CVSS 10): Unauthenticated Arbitrary File Write Hits 900k W3 Total Cache Sites
CyberSIXT Evidence Panel
Article by CyberSIXT