Access Control Flaw in W3 Total Cache Plugin by BoldGrid
CVE-2026-27384
9CRITICAL
What is CVE-2026-27384?
The W3 Total Cache plugin by BoldGrid suffers from an access control vulnerability that stems from improper validation of specified input quantities. This flaw can allow unauthorized access to functionalities that are not adequately restricted by Access Control Lists (ACLs), potentially leading to execution of arbitrary code. Users of W3 Total Cache versions up to and including 2.9.1 should take immediate action to review their plugin settings and upgrade to the latest version to mitigate the risk posed by this vulnerability.
Affected Version(s)
W3 Total Cache 0 <= 2.9.1