securityonline.info 8/19/2026, 10:21:30 AM · external

CVE-2026-18051 (CVSS 10): Unauthenticated Arbitrary File Write Hits 900k W3 Total Cache Sites

CVE-2026-18051 (CVSS 10): Unauthenticated Arbitrary File Write Hits 900k W3 Total Cache Sites
CyberSIXT Evidence Panel
Primary Source wpscan.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THE page reports on a critical vulnerability identified as CVE-2026-18051 in the W3 Total Cache plugin, affecting WordPress sites running versions before 2.10.5. This vulnerability allows unauthenticated attackers to write files anywhere on the server, including the ability to overwrite .htaccess files, posing serious security risks. The flaw has a perfect CVSS score of 10, indicating its severe impact. Users are advised to update to version 2.10.5 immediately, as no confirmed exploitation has been reported yet. Detailed mitigation steps include checking .htaccess files for unauthorized changes after patching.

View Primary Source Via securityonline.info

Article by CyberSIXT