CVE-2026-57623Disclosure

MEDIUMCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1284

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-07-02); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-02: 1Mentions · 2026-07-22: 1Mentions · 2026-08-03: 1PoC Mentioned / Linked · 2026-07-22: 1Exploit Tool / Code · 2026-07-22: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-22: 1Technical Details · 2026-08-03: 107-0207-2208-03
Signal classification3 categories
Disclosure
133.3%
PoC
133.3%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-021
Disclosure1
2026-07-221
PoC1
2026-08-031
General1
Full discourse3 posts
  • ET Labs@ET_Labs
    General

    10 new OPEN, 28 new PRO (10 + 18) Lumma Stealer, CVE-2026-57623 (Wordpress W3 Cache RCE), CVE-2025-71334 (Flowise Directory Traversal), and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-08-03-v11248/3407

    Post summary

    The post lists new CVEs with brief vulnerability types but contains no PoC, exploit code, patch information, or evidence of active exploitation.

    03040348
    5.7K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-57623-w3-total-cache-version-2-9-4-high-vulnerability-proof-of-concept CVE-2026-57623 w3-total-cache (CVSS Score 8.1) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge…

    Post summary

    The post highlights a proof‑of‑concept for CVE‑2026‑57623 affecting the W3 Total Cache WordPress plugin, providing its CVSS score but offering no evidence of active exploitation, patch status, or mitigation details.

    0000043
    11 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Unauthenticated Remote Code Execution in W3 Total Cache (CVE-2026-57623) W3 Total Cache for WordPress contains an unauthenticated arbitrary code execution flaw affecting the W3 Total Cache plugin component in versions up to and including 2.9.4. The issue stems from improper input validation leading to unsafe code execution (RCE) through a plugin-exposed endpoint or action. An attacker can exploit this remotely over the network without authentication by sending crafted requests that trigger execution of attacker-controlled code. Successful exploitation enables full site compromise, including remote code execution on the web server, data theft/modification, and potential service disruption. 👉 Affected: W3 Total Cache <= 2.9.4 | Upgrade to a fixed release (not specified) or disable the plugin until a patch is available

    Post summary

    The post announces a critical, unauthenticated remote code execution vulnerability in W3 Total Cache up to v2.9.4 and recommends upgrading or disabling the plugin until a patch is released.

    0000095
    232 followersView on X

Explore more