CVE-2026-5032Disclosure

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains "W3 Total Cache", which causes raw mfunc/mclude dynamic fragment HTML comments — including the W3TC_DYNAMIC_SECURITY security token — to be rendered in the page source. This makes it possible for unauthenticated attackers to discover the value of the W3TC_DYNAMIC_SECURITY constant by sending a crafted User-Agent header to any page that contains developer-placed dynamic fragment tags, granted the site has the fragment caching feature enabled. With the leaked W3TC_DYNAMIC_SECURITY token, an attacker can craft valid mfunc tags to execute arbitrary PHP code on the server, achieving remote code execution.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-02); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-02: 1Mentions · 2026-04-08: 1Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-04-08: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-08: 1Technical Details · 2026-08-19: 104-0204-0808-19
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-021
Disclosure1
2026-04-081
PoC1
2026-08-191
Disclosure1
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-5032 - high 🚨 W3 Total Cache <= 2.9.3 - Unauthenticated Dynamic Security Token Disclosure > The W3 Total Cache WordPress plugin through version 2.9.3 skips its entire output buf... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-5032 @pdnuclei #NucleiTempla...

    Post summary

    The tweet announces the high‑severity CVE‑2026‑5032 affecting W3 Total Cache up to version 2.9.3, describing it as an unauthenticated dynamic security token disclosure.

    00002264
    1.2K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-5032-w3-total-cache-version-2-9-3-high-vulnerability-proof-of-concept CVE-2026-5032 #WordPress plugin #vulnerability w3-total-cache #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post shares a proof‑of‑concept for CVE‑2026‑5032, affecting W3 Total Cache v2.9.3, highlighting a high‑severity issue with no current patch or active exploitation reported.

    0001040
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5032 The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entir… https://www.cve.org/CVERecord?id=CVE-2026-5032

    Post summary

    The analysis identifies CVE-2026-5032 as a disclosure of an information‑exposure vulnerability in the W3 Total Cache WordPress plugin, affecting versions up to 2.9.3, with no available exploit, PoC, patch, or active exploitation evidence provided.

    00000302
    56.9K followersView on X

Explore more