/Vulnerability Library

W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read

CVE-2026-9282
Verified

Description

W3 Total Cache WordPress plugin <= 2.9.4 contains a directory traversal caused by improper handling in setupSources function, letting unauthenticated attackers read arbitrary files, exploit requires manual minify mode enabled with specific filename.

Severity

High

CVSS Score

7.5

Exploit Probability

3%

Affected Product

w3-total-cache

Published Date

July 20, 2026

Template Author

0x_akoko

CVE-2026-9282.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-9282
CWE ID:
cwe-22

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/e92cc06d-006f-4bba-a4ef-b23d80c00085https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.9.4/Minify_MinifiedFileRequestHandler.php#L191https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.9.4/lib/Minify/Minify/Controller/MinApp.php#L108

Remediation Steps

Update to the latest version beyond 2.9.4.