CVE-2026-27384Patch

MEDIUMCVSS 9.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects W3 Total Cache: from n/a through <= 2.9.1.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1284

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-13: 1Mentions · 2026-04-06: 1Active Exploitation · 2026-04-06: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-13: 1Technical Details · 2026-04-06: 103-0503-1304-06
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-131
Patch1
2026-04-061
Patch1
Full discourse3 posts
  • SwissWPSecure@Swisswpsecure
    Patch

    🔴 WP ALERT — April 6, 2026 4 active CVEs. Act today: 🔴 W3 Total Cache CVE-2026-27384 (CVSS 9.8) — RCE, no login needed → update to 2.9.2 🔴 Royal Elementor CVE-2026-28135 — no reliable patch → DELETE it 🟠 Gutenverse CVE-2026-2924 — Stored XSS → update to 3.4.7 🟠 Ally CVE-2026-2413 — blind SQLi, unauthenticated → update to 4.0.4+ Exploits hit in 5hrs median. SwissWPSuite WAF + Sentinel blocks 3 of 4. Royal Elementor must be deleted — we tell you the truth. Full brief → https://swisswpsecure.com/%f0%9f%94%b4-wordpress-security-alert-april-6-2026-4-active-threats-you-must-act-on-today/ #WPSec #WordPress 🛡️

    Post summary

    The alert announces four active WordPress CVEs, provides patches or deletions, and notes that exploits are underway in the wild.

    0001049
    1 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    CVE-2026-27384 — Critical vulnerability in the #WordPress W3 Total Cache plugin An improper input validation flaw in W3 Total Cache ≤ 2.9.1 can allow attackers to bypass access controls and potentially execute unauthorized functionality on the site. ⚠️ Why it matters: The plugin is widely used for performance optimization, so a flaw here can expose many WordPress sites to compromise. 🛠 Mitigation: Update to W3 Total Cache 2.9.2 or later immediately and review server logs for suspicious activity. #WordPressSecurity #CVE #WebSecurity #Malware #CyberThreats #FullPerimeterProtection #SilentRisk

    Post summary

    The post announces a critical improper‑input validation flaw in W3 Total Cache (versions ≤ 2.9.1) that could enable attackers to bypass access controls, and recommends updating to version 2.9.2 or later.

    0000049
    36 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27384 Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by … https://www.cve.org/CVERecord?id=CVE-2026-27384

    Post summary

    The text provides a brief CVE announcement for CVE-2026-27384, describing an input-validation issue in BoldGrid W3 Total Cache, without any PoC, exploit, or patch information.

    00000173
    56.6K followersView on X

Explore more