Critical severity10.0NVD Advisory· Published Aug 19, 2026· Updated Aug 26, 2026
CVE-2026-18051
CVE-2026-18051
Description
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.10.5
Patches
Vulnerability mechanics
References
1News mentions
2- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 17, 2026 to August 23, 2026)Wordfence Blog · Aug 27, 2026
- ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Hacker News · Aug 24, 2026