{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/w3-total-cache--2.10.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:w3-edge:w3_total_cache:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-78438"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["W3 Total Cache (\u003c= 2.10.5)"],"_cs_severities":["high"],"_cs_tags":["web-security","xss","wordpress","cve-2026-78438"],"_cs_type":"advisory","_cs_vendors":["W3 EDGE"],"content_html":"\u003cp\u003eThe W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the LazyLoad Background Mutator feature. This flaw, tracked as CVE-2026-78438, affects all versions up to and including 2.10.5. The vulnerability stems from insufficient input sanitization and output escaping within the plugin's image processing logic. An unauthenticated attacker can inject malicious web scripts into the comment content of a WordPress site. For the exploit to trigger, the target site must have the \u0026quot;Lazy Load Images\u0026quot; feature enabled with the \u0026quot;Process background images\u0026quot; option active. Furthermore, the injected comment must be approved by a moderator before the script becomes active in the front-end rendering of the page, where it will then execute in the context of any user who accesses the compromised page. This vulnerability poses a significant risk for session hijacking, credential theft, or unauthorized actions performed on behalf of legitimate users or administrators.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary scripts in the browsers of users viewing the injected content. This could result in unauthorized administrative actions, the theft of sensitive session cookies, or the redirection of users to malicious infrastructure. The impact is elevated if a site administrator views the injected content, potentially leading to a full site compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the W3 Total Cache plugin to a version beyond 2.10.5 immediately to resolve CVE-2026-78438.\u003c/li\u003e\n\u003cli\u003eDisable the \u0026quot;Process background images\u0026quot; option within the \u0026quot;Lazy Load Images\u0026quot; settings until the update can be applied.\u003c/li\u003e\n\u003cli\u003eAudit comment sections for suspicious content, specifically checking for script tags or encoded payloads in comment metadata.\u003c/li\u003e\n\u003cli\u003eImplement or review Content Security Policy (CSP) headers to restrict the execution of unauthorized inline scripts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T07:30:53Z","date_published":"2026-09-05T07:30:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-w3-total-cache-xss/","summary":"The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the LazyLoad Background Mutator, allowing unauthenticated attackers to execute arbitrary scripts after moderator approval.","title":"Stored XSS in W3 Total Cache Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-09-w3-total-cache-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - W3 Total Cache (\u003c= 2.10.5)","version":"https://jsonfeed.org/version/1.1"}