PT-2026-86335 · Boldgrid · W3 Total Cache
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
If you run a WordPress site, you gotta stop whatever you are doing and check your dashboard immediately.
So I was just looking through the Wordfence database and found a crazy vulnerability in W3 Total Cache, that huge plugin with almost a million active installs. We are talking about an unauthenticated Stored Cross-Site Scripting flaw, CVE-2026-78438, affecting every single version up to 2.10.5.
This thing gets a 7.2 severity score which is insane because an attacker does not even need to be logged in to inject malicious script through the lazy load background mutator and compromise your site. Imagine waking up to find your site or your client sites injected with spam or malware just because of a missed update.
Go check your installed plugins right now and update that thing to the latest version before someone takes advantage of it. Stay safe out there guys, this stuff is no joke.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
W3 Total Cache