Other
9 records28.1%First: 2014. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 32 vulnerability records associated with W3 Total Cache, published between 2014 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 4 | |
| 2016 | 7 | |
| 2019 | 3 | |
| 2020 | 4 | |
| 2021 | 3 | |
| 2022 | 1 | |
| 2024 | 1 | |
| 2025 | 4 | |
| 2026 | 5 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 6.3% |
| High | 16 | 50% |
| Medium | 12 | 37.5% |
| Low | 2 | 6.3% |
First: 2014. Latest: 2026.
First: 2016. Latest: 2026.
First: 2014. Latest: 2021.
First: 2025. Latest: 2026.
First: 2014. Latest: 2014.
First: 2016. Latest: 2016.
First: 2016. Latest: 2016.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
2.10.02.9.42.9.22.8.132.8.22.7.62.2.32.1.52.1.42.1.30.9.40.9.2.50.9.7.40.9.50.9.4.10.9.2.9Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.9.4 | W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter | July 10, 2026 | 2.10.0 | High |
*-2.9.4 | W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary Code Execution | June 29, 2026 | 2.10.0 | High |
*-2.9.3 | W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header | April 1, 2026 | 2.9.4 | High |
*-2.9.1 | W3 Total Cache <= 2.9.1 - Missing Authorization | March 12, 2026 | 2.9.2 | Medium |
*-2.9.1 | W3 Total Cache <= 2.9.1 - Unauthenticated Arbitrary Code Execution | February 24, 2026 | 2.9.2 | Critical |
*-2.8.12 | W3 Total Cache <= 2.8.12 - Unauthenticated Command Injection | October 27, 2025 | 2.8.13 | High |
*-2.8.1 | W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery | January 13, 2025 | 2.8.2 | High |
*-2.8.1 | W3 Total Cache <= 2.8.1 Information Exposure via Log Files | January 13, 2025 | 2.8.2 | Medium |
*-2.8.1 | W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation | January 13, 2025 | 2.8.2 | Medium |
*-2.7.5 | W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext | September 23, 2024 | 2.7.6 | Low |
*-2.2.2 | Guzzle <= 6.5.7 and 7.0-7.4.4 - Information Exposure | June 20, 2022 | 2.2.3 | High |
0.5-2.1.4 | W3 Total Cache <= 2.1.4 - Reflected Cross-Site Scripting via extension | June 28, 2021 | 2.1.5 | High |
[*, 2.1.4) | W3 Total Cache <= 2.1.3 - Reflected Cross-Site Scripting via extension | June 28, 2021 | 2.1.4 | Medium |
[*, 2.1.3) | W3 Total Cache <= 2.1.2 Authenticated (Admin+) Stored Cross-Site Scripting | June 16, 2021 | 2.1.3 | Medium |
0.9.2.6-0.9.3 | W3 Total Cache 0.9.2.6-0.9.3 - File Read / Directory Traversal | December 22, 2020 | 0.9.4 | High |
*-0.9.2.4 | W3 Total Cache <= 0.9.2.4 - Insecure Cryptography to Sensitive Information Disclosure | September 22, 2020 | 0.9.2.5 | High |
*-0.9.2.4 | W3 Total Cache <= 0.9.2.4 - Sensitive Information Exposure | September 22, 2020 | 0.9.2.5 | High |
*-0.9.2.4 | W3 Total Cache <= 0.9.2.4 - Password Hash Extraction | September 22, 2020 | 0.9.2.5 | High |
*-0.9.7.3 | W3 Total Cache <= 0.9.7.3 - Server Side Request Forgery | May 22, 2019 | 0.9.7.4 | Medium |
*-0.9.7.3 | W3 Total Cache plugin <= 0.9.7.3 - Reflected Cross-Site Scripting | May 7, 2019 | 0.9.7.4 | Medium |
*-0.9.7.3 | W3 Total Cache <= 0.9.7.3 - Improper Input Validation via openssl_verify | May 7, 2019 | 0.9.7.4 | Medium |
*-0.9.4.1 | W3 Total Cache <= 0.9.4.1 - Weak validation of Amazon SNS push messages | November 10, 2016 | 0.9.5 | High |
*-0.9.4 | W3 Total Cache <= 0.9.4 - Server-Side Request Forgery leading to Host Information Disclosure | October 31, 2016 | 0.9.5 | High |
*-0.9.4.1 | W3 Total Cache <= 0.9.4.1 - Arbitrary Code Execution via settings import | September 26, 2016 | 0.9.5 | High |
*-0.9.4.1 | W3 Total Cache <= 0.9.4.1 - Authenticated Arbitrary File Download | September 26, 2016 | 0.9.5 | Medium |
Selected source records
Published: July 10, 2026
Published: June 29, 2026
Published: April 1, 2026
Published: March 12, 2026
Published: February 24, 2026
Published: October 27, 2025
Published: January 13, 2025
Published: January 13, 2025
Published: August 1, 2014
Published: February 24, 2026
Published: September 8, 2014
Published: September 26, 2016
Published: October 31, 2016
Published: January 13, 2025
Published: October 27, 2025
Published: June 29, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.