CRITICAL 10 CVE-2026-18051 Published 19 Aug 2026

WordPress W3 Total Cache File Overwrite Vulnerability

Worried this affects one of your servers?

The W3 Total Cache WordPress plugin, before version 2.10.5, has a security flaw that allows unauthenticated attackers to write files into any existing directory on the server, including outside the web root, by manipulating the request path used to build cache file names.

On Apache servers, this vulnerability can overwrite the site's .htaccess files, breaking the site and potentially stripping hardening rules that other security measures rely on.

Reference: CVE-2026-18051 on NVD

← Back to Security News