What is CVE-2026-18109?
The W3 Total Cache plugin for WordPress has a Stored XSS vulnerability via the "Comment Author Name" field in all versions up to 2.10.3 due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject arbitrary web scripts through the comment author name. Updating the plugin to the latest version is recommended.
Azərbaycanca: WordPress-in W3 Total Cache plaqininin 2.10.3 versiyasına qədər olan bütün versiyalarında "Comment Author Name" sahəsi vasitəsilə Stored XSS zəifliyi aşkarlanıb. Bu, autentifikasiya olunmamış hücumçulara şərh müəllif adına ixtiyari veb skriptlər yerləşdirməyə imkan verir. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What does the CVE-2026-18109 vulnerability in W3 Total Cache allow unauthenticated attackers to do?
Inject arbitrary web scripts through the comment author name field.
Which versions of the W3 Total Cache plugin are affected by the CVE-2026-18109 Stored XSS vulnerability?
All versions up to 2.10.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.