Skip to content

Known CVE

W3 Total Cache <= 2.9.3 - Unauthenticated Dynamic Security Token Disclosure

The W3 Total Cache WordPress plugin through version 2.9.3 skips its entire output buffering and processing pipeline whenever an incoming request's User-Agent header contains the string "W3 Total Cache", without authenticating the caller. On sites that use developer-placed dynamic fragment tags, the raw mfunc/mclude HTML comments - which embed the per-site W3TC_DYNAMIC_SECURITY token - are therefore rendered directly into the page source instead of being processed and stripped, letting an unauthenticated attacker harvest the token by comparing a normal response against one sent with the magic User-Agent.

CVE-2026-5032

High2026CVSS 7.5CWE-200

cve2026 · wordpress · wp-plugin · wp · w3-total-cache · exposure · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website