CVE-2026-18051Disclosure

HIGHCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 3 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 7 mentions (2026-08-19); latest day: 1
  • 11 total mentions across 3 days

Deep dive

Activity timeline11 mentions / 3d
02457Mentions · 2026-08-19: 7Mentions · 2026-08-20: 3Mentions · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-19: 2PoC Mentioned / Linked · 2026-08-20: 1Exploit Tool / Code · 2026-08-20: 1Active Exploitation · 2026-08-19: 1Active Exploitation · 2026-08-21: 1Patch / Workaround · 2026-08-19: 4Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-19: 6Technical Details · 2026-08-20: 2Technical Details · 2026-08-21: 108-1908-2008-21
Signal classification5 categories
Disclosure
545.5%
General
218.2%
Patch
218.2%
PoC
19.1%
Active Exploitation
19.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-197
Disclosure4General1Patch2
2026-08-203
Disclosure1General1PoC1
2026-08-211
Active Exploitation1
Full discourse11 posts
  • Koichi@x64koichi
    Active Exploitation

    やけに改竄サイトが増えてるなと思ったら、やはり。 CVE-2026-18051 (CVSS 10)だけをとっても、脆弱な対象サイトは90万サイト! https://thehackernews.com/2026/08/stopandprotect-uses-nearly-2000-hacked.html https://securityonline.info/w3-total-cache-file-write-cve-2026-18051/

    Post summary

    The post indicates that CVE-2026-18051 is being actively exploited in the wild, with evidence of nearly 2,000 hacked sites and a total of 900,000 vulnerable sites exposed.

    265421017451.3K
    3.4K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    CVE-2026-18051 (CVSS 10) is an unauthenticated arbitrary file write in W3 Total Cache, exposing 900k+ WordPress sites. Update to 2.10.5. #W3TotalCache #WordPress #CVE202618051 #PathTraversal #InfoSec https://securityonline.info/w3-total-cache-file-write-cve-2026-18051/

    Post summary

    CVE‑2026‑18051 allows unauthenticated arbitrary file writes in W3 Total Cache, affecting over 900k WordPress sites; updating to v2.10.5 is recommended.

    5320110768.6K
    13.0K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    90万サイト以上が使用するWordPressのW3 Total CacheにCVSSスコア10の脆弱性。CVE-2026-18051は無認証での任意ディレクトリファイル書き込み。キャッシュファイル名をリクエストパスから作っているのにそのパスを検証しないのが悪い。.htaccessを書き換えたりして遊べる。 https://securityonline.info/w3-total-cache-file-write-cve-2026-18051/

    Post summary

    The post announces a CVSS 10 unauthenticated arbitrary file‑write flaw in WordPress's W3 Total Cache, links to a detailed write‑up, but makes no claims of active exploitation or available patch.

    0511761.7K
    7.8K followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 CRITICAL: CVE-2026-18051 reportedly exposes 900K+ WordPress sites through an unauthenticated arbitrary file write flaw in W3 Total Cache. The vulnerability can potentially lead to server compromise, making exposed installations a high-priority target. 🔴 Update W3 Total Cache to 2.10.5 immediately. #WordPress #W3TotalCache #CVE #CyberSecurity #WebSecurity #Infosec

    Post summary

    A critical CVE affecting WordPress sites is reported, with evidence of widespread exploitation; a patch (v2.10.5) is immediately recommended.

    0001983.3K
    1.6K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🔴 WordPress W3 Total Cache eklentisinde kritik güvenlik açığı! - CVE-2026-18051 (CVSS: 10) WordPress'in yaygın kullanılan W3 Total Cache eklentisinde kritik bir güvenlik açığı duyuruldu. Kimlik doğrulaması olmadan (unauthenticated) keyfi dosya yazma (arbitrary file write) açığı mevcut. Path traversal ile de ilişkilendirilmiş. 900.000'den fazla WordPress sitesini etkiliyor. Eklentiyi 2.10.5 sürümüne acilen güncelleyin.

    Post summary

    A critical, unauthenticated arbitrary file write vulnerability (CVE‑2026‑18051) was disclosed in the WordPress W3 Total Cache plugin, affecting over 900,000 sites; users are urged to upgrade to version 2.10.5 immediately.

    030138994
    2.4K followersView on X
  • 大島義裕@yoshihiro_oh
    Disclosure

    WordPressプラグイン「W3 Total Cache」に脆弱性が公開されました https://nvd.nist.gov/vuln/detail/CVE-2026-18051 ・脆弱性の種類: パス・トラバーサル (CWE-22) ・深刻度: 緊急 (Critical) ・影響を受けるバージョン: 2.10.5 未満のすべてのバージョン ・攻撃元区分: ネットワーク経由、認証不要(権限は一切不要)

    Post summary

    A critical path traversal vulnerability (CVE-2026-18051) has been disclosed affecting WordPress plugin W3 Total Cache versions below 2.10.5, exploitable remotely without authentication.

    0211501.0K
    2.0K followersView on X
  • 1dayexploit@1dayexploit
    PoC

    🔥 W3 Total Cache: Unauthenticated Arbitrary File Write Analysis 🔴 CVE-2026-18051 🔴 🗓️ Publish Date: 20 Aug 2026 ÂLIM rebuilt it, wrote a proof of concept, and confirmed it fires on the vulnerable build and stays silent on the patched one. W3 Total Cache has patched CVE-2026-18051. Every version before 2.10.5 on the default Disk: Enhanced page cache lets an unauthenticated request write a file into any existing directory, inside or outside the web root. No login, no token, no click. The advisory's ".htaccess overwrite" half does not fire on a stock install. We checked: after a successful write the site .htaccess was byte for byte unchanged. 🔎 Full Technical Analysis and PoC: CVE-2026-18051: https://1dayexploit.com/blog/cve-2026-18051-w3-total-cache-arbitrary-file-write/ Fixed in 2.10.5. -- #W3TotalCache #WordPress #1dayexploit #ALIM #PathTraversal #RedTeam #OffSec #VulnerabilityResearch #CyberSecurity #InfoSec #AppSec #Exploit

    Post summary

    The post announces CVE-2026-18051 in W3 Total Cache, presents a working proof of concept for arbitrary file writes, and confirms the vulnerability is patched in version 2.10.5.

    12051211
    51 followersView on X
  • Mustafa Can İPEKÇİ@mcipekci
    General

    @OliverSild Lol this is CVSS 9.0 but CVE-2026-18051 is CVSS 10.0, still not being able to understand how.

    Post summary

    The text simply notes a difference in CVSS scores for CVE-2026-18051 with no additional context or actionable details.

    10020498
    8.8K followersView on X
  • パッチくん🐾WordPressの見張り係@patchkun_jp
    General

    一次情報はこっち。CVE-2026-18051、報告はWPScan。 https://nvd.nist.gov/vuln/detail/CVE-2026-18051

    Post summary

    The message reports CVE-2026-18051 and cites WPScan as the reporter, but does not provide any further details about PoC, exploit, patch, or technical aspects.

    0001059
    26 followersView on X
  • HideSZK@45Hrsg
    Disclosure

    CVE-2026-18051 (CVSS 10): Unauthenticated Arbitrary File Write Hits 900k W3 Total Cache Sites https://securityonline.info/w3-total-cache-file-write-cve-2026-18051/

    Post summary

    The post announces CVE‑2026‑18051, a CVSS 10 vulnerability that allows unauthenticated arbitrary file writes on about 900,000 sites running the W3 Total Cache plugin, and directs readers to a link for more details.

    0000096
    20 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🚨 **900,000+ WORDPRESS SITES USE A PLUGIN HIT BY A CRITICAL UNAUTHENTICATED FILE-WRITE FLAW** **CyberSignal Daily ✓ · 🌐 WordPress / Web Security · August 19, 2026** 🎯 **A newly assigned CVE affects one of WordPress's most widely deployed performance plugins — and an attacker doesn't need a WordPress account to trigger the underlying flaw on a vulnerable installation.** The vulnerability is: 🚨 **CVE-2026-18051** 📦 Product: **W3 Total Cache** ⚠️ Affected: **versions before 2.10.5** ✅ Fixed: **2.10.5** 🌐 Authentication: **Not required** WPScan rates the vulnerability **CVSS 10.0 / Critical**. The CVE record itself entered public vulnerability databases on **August 19**, although WPScan's underlying research was published August 17. And the potential exposure is significant. According to the official WordPress plugin directory, **W3 Total Cache has more than 900,000 active installations**. That does **not** mean 900,000 sites are currently vulnerable—many may already be running the fixed release—but it illustrates the potential scale of the affected software ecosystem. ### 🔥 WHAT IS THE VULNERABILITY? W3 Total Cache is designed to improve website performance by caching pages and other content. The problem involves the way vulnerable versions construct filenames for cached pages. WPScan found that the plugin failed to properly validate part of the incoming request path before using it to determine where a cache file should be written. That creates a **path-traversal / arbitrary-file-write condition**. In practical terms, an unauthenticated attacker interacting with a vulnerable website may be able to make the plugin write a file into an **existing directory elsewhere on the server**, including locations outside the normal cache directory. That is much more serious than simply corrupting one cached webpage. ### 🗂️ WHY ARBITRARY FILE WRITE MATTERS Applications normally need strict boundaries around where they can write files. A caching plugin should essentially be saying: > “My cache files stay inside my cache directory.” With this flaw, that boundary could be broken. Depending on the server's configuration and filesystem permissions, the issue could result in existing files at the targeted location being overwritten. Apache deployments have an additional problem. WPScan says the vulnerability can be used to overwrite **`.htaccess` files**. Those files are frequently used by Apache websites for: 🔐 access-control rules 🔀 URL rewriting 🛡️ security restrictions ⚙️ application configuration. Overwriting them could break portions of a website or remove server-side hardening rules that other security controls depend upon. ### 😬 THE ATTACK DOESN'T REQUIRE A LOGIN This is probably the most important characteristic for defenders. The flaw is: 🔴 remotely reachable through the web application 🔴 unauthenticated 🔴 present in W3 Total Cache versions below 2.10.5. An attacker therefore doesn't first need: ❌ an administrator account ❌ a subscriber account ❌ stolen WordPress credentials. That significantly increases the importance of patching exposed installations. ### 🔒 THE FULL PUBLIC PoC IS BEING DELAYED There is another interesting detail. WPScan says it is intentionally **withholding the public proof-of-concept until September 17, 2026**, giving WordPress administrators additional time to update vulnerable installations. That's responsible disclosure—and it also creates a very clear message: **The patch window is open now.** Defenders should use it. ### ✅ VERSION 2.10.5 FIXES THE ISSUE The official WordPress plugin page now lists: **W3 Total Cache 2.10.5** and its changelog specifically says the update keeps **Disk Enhanced page-cache file operations within the cache directory**. That description lines up directly with the security problem identified by WPScan. ### 🚨 IMPORTANT: NO CONFIRMED MASS EXPLOITATION YET This distinction matters. At the time of the sources reviewed for this post: ❌ I found no reliable evidence establishing widespread active exploitation of CVE-2026-18051. ❌ It is not appropriate to claim that 900,000 websites have been hacked. ❌ The 900,000+ figure represents **active plugin installations**, not confirmed vulnerable or compromised sites. The accurate headline is: ✅ **A critical vulnerability affects a plugin with 900,000+ active installations.** Not: ❌ **900,000 WordPress sites hacked.** ### 🛡️ WHAT WORDPRESS ADMINS SHOULD DO The priority is straightforward: ✅ Verify the installed W3 Total Cache version ✅ Upgrade to **2.10.5 or newer** ✅ Review unexpected modifications to server configuration files if an older version was exposed ✅ Check web/server logs for unusual activity ✅ Keep WordPress plugins updated rather than only updating WordPress core. The plugin's official directory currently lists **2.10.5** as the available fixed release. ### 📌 CURRENT STATUS 🔴 CVE-2026-18051 🔴 Unauthenticated vulnerability 🔴 Arbitrary file write / path traversal 🔴 Existing files may potentially be overwritten 🔴 Apache `.htaccess` files can be affected 🔴 W3 Total Cache has 900,000+ active installations 🔴 Versions before 2.10.5 affected 🟢 Version 2.10.5 fixes the issue 🟢 Public PoC delayed until September 17 ⚪ No confirmed widespread exploitation identified in the sources reviewed This is exactly the type of WordPress vulnerability worth watching because **a security issue inside an extremely popular plugin can create an enormous potential attack surface overnight.** 🔗 **Sources:** WPScan • http://WordPress.org Plugin Directory • CVE/NVD ecosystem • August 19 SecurityOnline reporting #CyberSecurity #WordPress #W3TotalCache #CVE #WebSecurity #Vulnerability #AppSec #PatchNow #CyberNews #InfoSec

    Post summary

    CVE‑2026‑18051 is a critical unauthenticated arbitrary file‑write flaw in W3 Total Cache; a patch (2.10.5) is released, a PoC will be published later, and there is no evidence of active exploitation yet.

    00000163
    82 followersView on X

Explore more