← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 14, 2026 · 02:25via CVEFeed

CVE-2026-18109 - W3 Total Cache = 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name

Brief

CVE ID : CVE-2026-18109

Published : Aug. 14, 2026, 2:25 a. m.

  • 39 minutes ago

Description : The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.

  • 3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step.

Severity: 0.0

  • NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed