CVE-2026-18109Disclosure

LOWCVSS 7.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-14); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-14: 2Mentions · 2026-08-18: 1Active Exploitation · 2026-08-18: 1Technical Details · 2026-08-14: 208-1408-18
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-142
Disclosure2
2026-08-181
Active Exploitation1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-18109 The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insuf… https://www.cve.org/CVERecord?id=CVE-2026-18109

    Post summary

    CVE-2026-18109 is a stored cross‑site scripting issue in W3 Total Cache plugin for WordPress up to version 2.10.3. The post merely records the vulnerability without providing PoC, exploit, or mitigation details.

    000101.6K
    57.9K followersView on X
  • PJ@Npj8448
    Active Exploitation

    🚨 Healthcare Giant CareCloud Suffers Massive Data Breach Affecting 345,000 Patients; WordPress Plugin CVE-2026-18109 Under Active Exploitation. https://pranithjain.qzz.io/threatintel/social/firehose

    Post summary

    The post reports that CareCloud suffered a significant data breach affecting 345,000 patients, attributing the breach to the WordPress plugin CVE-2026-18109, which is claimed to be under active exploitation.

    0000037
    63 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-18109 The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insuf… https://www.cve.org/CVERecord?id=CVE-2026-18109 ----- Traducción: CVE-2026-18109 El … https://infoflow.cloud`

    Post summary

    The passage discloses that CVE-2026-18109 is a stored XSS flaw in W3 Total Cache up to v2.10.3, without reference to PoCs, exploits, patches, or active attacks.

    0000041
    98 followersView on X

Explore more