CVE-2026-18051
Last modified
CVE-2026-18051 is a critical-severity vulnerability rated 10/10 on the CVSS scale. The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | W3 Total Cache | < 2.10.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-18051?
How severe is CVE-2026-18051?
How do I fix CVE-2026-18051?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18046The Cookie Consent WordPress plugin before 0.0.10 does not …4.3
- CVE-2026-18047A flaw was found in Dogtag PKI's ACME responder where the we…6.5
- CVE-2026-18048The WP Photo Album Plus WordPress plugin before 9.2.07.002 d…7.5
- CVE-2026-18049The WP Photo Album Plus WordPress plugin before 9.2.07.002 d…7.5
- CVE-2026-1805The DA Media GigList plugin for WordPress is vulnerable to S…6.4
- CVE-2026-18050The Events Manager WordPress plugin before 7.4 does not per…7.5
- CVE-2026-18052The ManageWP Worker WordPress plugin before 4.9.37 does not …8.1
- CVE-2026-18056The HivePress Authentication plugin for WordPress is vulnera…7.5
- CVE-2026-18057The Events Manager WordPress plugin before 7.4.1 does not s…8.1
- CVE-2026-18058The mobile Smart Connect dashboard UI was subject to manipul…7.5
- CVE-2026-18059The PixelYourSite – Your smart PIXEL (TAG) & API Manager plu…5.3
- CVE-2026-1806The Tour & Activity Operator Plugin for TourCMS plugin for W…6.4
Are you affected by CVE-2026-18051?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
