Unauthenticated Path Traversal in W3 Total Cache by W3 Edge
CVE-2026-66695

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 August 2026

What is CVE-2026-66695?

An unauthenticated path traversal vulnerability exists in versions of W3 Total Cache up to 2.10.2, allowing attackers to access sensitive files on the server. This flaw can be exploited without prior authentication, potentially exposing critical information and compromising website security.

Affected Version(s)

W3 Total Cache <= 2.10.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mykel Nelson | Patchstack Bug Bounty Program
.