W3 Total Cache <= 2.9.3 - Unauthenticated Dynamic Security Token Disclosure
CVE-2026-5032
Verified
Description
The W3 Total Cache WordPress plugin through version 2.9.3 skips its entire output buffering and processing pipeline whenever an incoming request's User-Agent header contains the string "W3 Total Cache", without authenticating the caller. On sites that use developer-placed dynamic fragment tags, the raw mfunc/mclude HTML comments - which embed the per-site W3TC_DYNAMIC_SECURITY token - are therefore rendered directly into the page source instead of being processed and stripped, letting an unauthenticated attacker harvest the token by comparing a normal response against one sent with the magic User-Agent.
Severity
High
CVSS Score
7.5
Exploit Probability
3%
Affected Product
w3-total-cache
Published Date
August 3, 2026
Template Author
prithvee07
CVE-2026-5032.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-5032
CWE ID:
cwe-200
References
https://github.com/advisories/GHSA-fxg7-rh9m-q77phttps://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.9.3/Generic_Plugin.php#L1016https://plugins.trac.wordpress.org/changeset/3495959/w3-total-cachehttps://www.wordfence.com/threat-intel/vulnerabilities/id/a65eb62d-847b-4f3a-848b-1290e3118c01?source=cvehttps://nvd.nist.gov/vuln/detail/CVE-2026-5032
Remediation Steps
Update the W3 Total Cache plugin to version 2.9.4 or later.