CVE-2026-18109

W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step.


We have discovered 25,645 live websites that are affected by CVE-2026-18109.

Run a Free Instant Scan




Affected Software

Product  W3 Total Cache
Category Cache Tools
Vulnerable Domains25,645 live websites (100% of W3 Total Cache install base)
Vulnerable Versions
  • from 0 through 2.10.3
Vulnerable Versions Count110 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 14, 2026
  • Updated - Aug 14, 2026

Credits

  • daroo (finder)

Website Distribution by Country

Number of websites using CVE-2026-18109
United States9,726 websites



Germany3,122 websites
GB1,063 websites
Netherlands972 websites
France966 websites
Italy932 websites
Canada703 websites
Slovakia669 websites
Australia525 websites
Poland475 websites

Website Distribution by TLD

Number of websites using CVE-2026-18109
.com11,907 websites
.de2,001 websites
.org818 websites
.nl800 websites
.it696 websites
.co.uk673 websites
.net655 websites
.ca483 websites
.com.au476 websites
.fr383 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18109

Top websites that are affected by CVE-2026-18109. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.eu Cyprus*,***
*********.com United States*,***
************.com United States*,***
*********.com United States*,***
**********.com United States*,***
**********.com United States**,***
****************.com United States**,***
*******************.com United States**,***
********.com Germany**,***
********.com United States**,***
See full domain list

FAQ

CVE-2026-18109 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in W3 Total Cache
A total of 25,645 websites have been identified as vulnerable to CVE-2026-18109, based on global website indexing conducted by WebTechSurvey.
The W3 Total Cache is affected by the CVE-2026-18109 vulnerability.
W3 Total Cache versions up to and including 2.10.3 are vulnerable to CVE-2026-18109.

References