W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read
CVE-2026-9282
Verified
Description
W3 Total Cache WordPress plugin <= 2.9.4 contains a directory traversal caused by improper handling in setupSources function, letting unauthenticated attackers read arbitrary files, exploit requires manual minify mode enabled with specific filename.
Severity
High
CVSS Score
7.5
Exploit Probability
3%
Affected Product
w3-total-cache
Published Date
July 20, 2026
Template Author
0x_akoko
CVE-2026-9282.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-9282
CWE ID:
cwe-22
References
https://www.wordfence.com/threat-intel/vulnerabilities/id/e92cc06d-006f-4bba-a4ef-b23d80c00085https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.9.4/Minify_MinifiedFileRequestHandler.php#L191https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.9.4/lib/Minify/Minify/Controller/MinApp.php#L108
Remediation Steps
Update to the latest version beyond 2.9.4.