PT-2026-29688 · WordPress · W3 Total Cache
Wesley
·
Published
2026-04-02
·
Updated
2026-04-05
·
CVE-2026-5032
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
W3 Total Cache versions up to and including 2.9.3
Description
The W3 Total Cache plugin for WordPress is susceptible to information disclosure. The plugin bypasses its output buffering and processing when the User-Agent header contains "W3 Total Cache", leading to the rendering of raw mfunc/mclude dynamic fragment HTML comments, including the
W3TC DYNAMIC SECURITY security token, in the page source. This allows unauthenticated attackers to discover the value of the W3TC DYNAMIC SECURITY constant by sending a crafted User-Agent header to pages with enabled fragment caching.Recommendations
Update W3 Total Cache to a version later than 2.9.3.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
W3 Total Cache