Stored Cross-Site Scripting Vulnerability in W3 Total Cache Plugin for WordPress
CVE-2026-78438
7.2HIGH
What is CVE-2026-78438?
The W3 Total Cache plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) attack due to inadequate input sanitization and output escaping. This vulnerability allows unauthenticated attackers to inject harmful scripts through comment content, which will execute when users access affected pages. It necessitates the activation of the 'Lazy Load Images' feature, along with 'Process background images,' in combination with the need for a moderator to approve the malicious comment prior to script execution.
Affected Version(s)
W3 Total Cache 0 <= 2.10.5