PT-2026-68592 · WordPress · W3 Total Cache

CVE-2026-66695

·

Published

2026-08-06

·

Updated

2026-08-06

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions W3 Total Cache versions prior to 2.10.3
Description An unauthenticated path traversal issue exists in the W3 Total Cache plugin. Path traversal is a flaw that allows an attacker to access files and directories that are stored outside the web root folder by manipulating variables that control a file path.
Recommendations Update W3 Total Cache to a version newer than 2.10.2.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66695

Affected Products

W3 Total Cache