CVE-2026-18109 - W3 Total Cache = 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name
Brief
CVE ID : CVE-2026-18109
Published : Aug. 14, 2026, 2:25 a. m.
- 39 minutes ago
Description : The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.
- 3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step.
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
