Access Control Flaw in W3 Total Cache Plugin by BoldGrid
CVE-2026-27384

9CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 March 2026

What is CVE-2026-27384?

The W3 Total Cache plugin by BoldGrid suffers from an access control vulnerability that stems from improper validation of specified input quantities. This flaw can allow unauthorized access to functionalities that are not adequately restricted by Access Control Lists (ACLs), potentially leading to execution of arbitrary code. Users of W3 Total Cache versions up to and including 2.9.1 should take immediate action to review their plugin settings and upgrade to the latest version to mitigate the risk posed by this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

W3 Total Cache <= n/a

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CODE WHITE GmbH | Patchstack Bug Bounty Program
.