PT-2026-29688 · WordPress · W3 Total Cache

Wesley

·

Published

2026-04-02

·

Updated

2026-04-05

·

CVE-2026-5032

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions W3 Total Cache versions up to and including 2.9.3
Description The W3 Total Cache plugin for WordPress is susceptible to information disclosure. The plugin bypasses its output buffering and processing when the User-Agent header contains "W3 Total Cache", leading to the rendering of raw mfunc/mclude dynamic fragment HTML comments, including the W3TC DYNAMIC SECURITY security token, in the page source. This allows unauthenticated attackers to discover the value of the W3TC DYNAMIC SECURITY constant by sending a crafted User-Agent header to pages with enabled fragment caching.
Recommendations Update W3 Total Cache to a version later than 2.9.3.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-5032

Affected Products

W3 Total Cache