HomeSecurityW3 Total Cache XSS: Critical vulnerability in WordPress websites

W3 Total Cache XSS: Critical vulnerability in WordPress websites

A new W3 Total Cache XSS vulnerability allows unauthenticated attackers to cache malicious JavaScript on WordPress pages as long as the Lazy Load Images feature is enabled. The issue was fixed in version 2.10.4, but installations that remain on an older version need immediate monitoring.

W3 Total Cache XSS vulnerability on WordPress website

The vulnerability is listed as CVE-2026-18109 and affects the W3 Total Cache plugin up to version 2.10.3. According to the NVD entry, the attack goes through the name of a comment author and is linked to the LazyLoad mutator's image tag rewriting process.

See also: WordPress: Serious vulnerability in the W3 Total Cache plugin

How the W3 Total Cache XSS vulnerability works

The issue falls under the category of Stored Cross-Site Scripting. Instead of the code being executed only when a request is made, it is stored in content that can be displayed to visitors again. In this case, the name of the author of a comment can carry the load when the Lazy Load Images feature processes the images on the page.

NVD rates CVE-2026-18109 as 7.2 on the CVSS 3.1 scale and high severity. The attacker does not need an account or interaction from the victim, and the attack is carried out over a network. The impact is mainly related to the confidentiality and integrity of the page, as malicious code can be executed in the browser of anyone visiting the infected content.

W3 Total Cache XSS and malicious code in WordPress

The Wordfence update describes the issue as an unauthenticated Stored XSS via author name. The limiting factor in the scenario is not the need for permissions, but the activation of Lazy Load Images. Thus, a site can be exposed even when administrators are not using other features of the plugin.

Version 2.10.4 fixes W3 Total Cache XSS

W3 Total Cache released version 2.10.4 on August 13. NVD’s entry links the fix to changes to the Lazy Load code and links to the project’s official changeset. The plugin’s page on WordPress.org now shows version 2.10.5, so upgrading to the latest available version is the safest option.

The W3 Total Cache XSS vulnerability does not require any complicated steps from the administrator to address. First, check the current version from the WordPress plugins page and install version 2.10.5 or later, when available. Then, clear the cache so that the pages are re-rendered with the corrected code.

See also: W3 Total Cache plugin: Vulnerability puts WordPress sites at risk

W3 Total Cache XSS Update in WordPress

What administrators should check

In addition to upgrading, administrators should review recent comments and pages generated with Lazy Load Images, looking for unusual characters or unexpected changes in markup. They should not delete items without a backup, but should keep the relevant files for review. In case of suspicious behavior, it is recommended to change administrative passwords and check accounts with access to WordPress.

Special care is needed on sites where comments are left open and pages are stored on a CDN or in multiple cache levels. The cache may retain old HTML after an upgrade, while a security mechanism that only checks the plugin files will not necessarily detect code within already cached content. The check should therefore also cover public versions of the pages.

The W3 Total Cache XSS vulnerability mainly concerns the interaction of two settings: comment posting and image processing by Lazy Load. Even if the site does not receive frequent comments, it is worth confirming that old entries do not contain unexpected HTML. Searching in logs, reviewing permissions, and testing on a copy of the site give a safer picture than a simple reinstall.

Installing the update is not enough if the copy of the page comes from an older, infected version. After the upgrade, you need to check the theme files, plugins and administrator accounts, as well as search for unexpected scripts on published pages. The SecNews technical team also recommends that automatic updates remain active only when the site has a test environment and a recent backup.

See also: How WordPress plugin vulnerabilities affect a website

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

CVE-2026-18109 shows once again that performance optimization features are part of the final attack surface of a WordPress site. Upgrading W3 Total Cache immediately and checking for past changes mitigates the risk without requiring disabling the entire caching mechanism.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS