What is CVE-2026-18051?
This vulnerability allows unauthenticated attackers to write arbitrary files to any existing directory on the server, as the W3 Total Cache plugin does not properly validate the request path used to build cache file names. Users should immediately update the plugin to version 2.10.5 or later to mitigate the risk.
Azərbaycanca: Bu boşluq W3 Total Cache plagini vasitəsilə təsdiqlənməmiş hücumçulara serverdə ixtiyari fayl yazmağa imkan verir, çünki plagin sorğu yolunu (request path) düzgün yoxlamır. Təsirə məruz qalmamaq üçün plagini dərhal 2.10.5 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
How is the vulnerability in W3 Total Cache (CVE-2026-18051) exploited?
The vulnerability allows unauthenticated attackers to write arbitrary files to any existing directory on the server because the plugin does not properly validate the request path.
What version should be updated to in order to protect against CVE-2026-18051?
To mitigate the risk, immediately update the W3 Total Cache plugin to version 2.10.5 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.