CVE-2026-18051

W3 Total Cache < 2.10.5 - Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page Cache Key

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.


We have discovered 25,645 live websites that are affected by CVE-2026-18051.

Run a Free Instant Scan




Affected Software

Product  W3 Total Cache
Category Cache Tools
Vulnerable Domains25,645 live websites (100% of W3 Total Cache install base)
Vulnerable Versions
  • from 0 through 2.10.5
Vulnerable Versions Count110 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')



Details

  • Published - Aug 19, 2026
  • Updated - Aug 19, 2026

Credits

  • Jakub Herman (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-18051
United States9,726 websites



Germany3,122 websites
GB1,063 websites
Netherlands972 websites
France966 websites
Italy932 websites
Canada703 websites
Slovakia669 websites
Australia525 websites
Poland475 websites

Website Distribution by TLD

Number of websites using CVE-2026-18051
.com11,907 websites
.de2,001 websites
.org818 websites
.nl800 websites
.it696 websites
.co.uk673 websites
.net655 websites
.ca483 websites
.com.au476 websites
.fr383 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18051

Top websites that are affected by CVE-2026-18051. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.eu Cyprus*,***
*********.com United States*,***
************.com United States*,***
*********.com United States*,***
**********.com United States*,***
**********.com United States**,***
****************.com United States**,***
*******************.com United States**,***
********.com Germany**,***
********.com United States**,***
See full domain list

FAQ

CVE-2026-18051 is Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in W3 Total Cache
A total of 25,645 websites have been identified as vulnerable to CVE-2026-18051, based on global website indexing conducted by WebTechSurvey.
The W3 Total Cache is affected by the CVE-2026-18051 vulnerability.
W3 Total Cache versions up to 2.10.5 are vulnerable to CVE-2026-18051.
CVE-2026-18051 is resolved in version 2.10.5 of W3 Total Cache.