Stored Cross-Site Scripting Vulnerability in W3 Total Cache Plugin for WordPress
CVE-2026-87920

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 October 2026

What is CVE-2026-87920?

The W3 Total Cache plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and output escaping. This flaw allows attackers to inject and execute arbitrary web scripts on affected pages, impacting users who visit these pages. The issue is particularly dangerous when the 'Remove query strings from static resources' option is activated, as it modifies the URL structure in a way that compromises the integrity of the attribute boundaries, enabling exploitation. Ensuring timely updates and proper configuration of the plugin can mitigate potential risks.

Affected Version(s)

W3 Total Cache 0 <= 2.10.6

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17y
.