/Vulnerability Library

W3 Total Cache <= 2.9.3 - Unauthenticated Dynamic Security Token Disclosure

CVE-2026-5032
Verified

Description

The W3 Total Cache WordPress plugin through version 2.9.3 skips its entire output buffering and processing pipeline whenever an incoming request's User-Agent header contains the string "W3 Total Cache", without authenticating the caller. On sites that use developer-placed dynamic fragment tags, the raw mfunc/mclude HTML comments - which embed the per-site W3TC_DYNAMIC_SECURITY token - are therefore rendered directly into the page source instead of being processed and stripped, letting an unauthenticated attacker harvest the token by comparing a normal response against one sent with the magic User-Agent.

Severity

High

CVSS Score

7.5

Exploit Probability

3%

Affected Product

w3-total-cache

Published Date

August 3, 2026

Template Author

prithvee07

CVE-2026-5032.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-5032
CWE ID:
cwe-200

References

https://github.com/advisories/GHSA-fxg7-rh9m-q77phttps://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.9.3/Generic_Plugin.php#L1016https://plugins.trac.wordpress.org/changeset/3495959/w3-total-cachehttps://www.wordfence.com/threat-intel/vulnerabilities/id/a65eb62d-847b-4f3a-848b-1290e3118c01?source=cvehttps://nvd.nist.gov/vuln/detail/CVE-2026-5032

Remediation Steps

Update the W3 Total Cache plugin to version 2.9.4 or later.