{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/w3-total-cache--2.10.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:w3_edge:w3_total_cache:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-87920"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["W3 Total Cache (\u003c= 2.10.6)"],"_cs_severities":["high"],"_cs_tags":["xss","web-application","wordpress","cve-2026-87920"],"_cs_type":"advisory","_cs_vendors":["W3 EDGE"],"content_html":"\u003cp\u003eThe W3 Total Cache plugin for WordPress, in versions up to and including 2.10.6, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability identified as CVE-2026-87920. The flaw resides within the Output-Buffer Regex Rewrite functionality, specifically the mutate_url() function. When the 'Remove query strings from static resources' configuration option is active, the plugin fails to perform sufficient input sanitization and output escaping.\u003c/p\u003e\n\u003cp\u003eAttackers can leverage this by crafting malicious input that disrupts attribute boundaries. Specifically, the mutate_url() function improperly strips the '?' delimiter and subsequent characters, which can include the closing quote of an HTML attribute. By manipulating this regex logic, an unauthenticated attacker can escape the intended attribute context and inject arbitrary JavaScript. This payload is then stored and executed in the browsers of users who visit the affected pages. The vulnerability is critical for WordPress administrators and users because it enables session hijacking, unauthorized actions, or site-wide content modification.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to inject arbitrary web scripts into WordPress pages. This could lead to the theft of administrative session cookies, redirection of users to malicious sites, or unauthorized modification of site content. Given the widespread use of W3 Total Cache, the potential attack surface is significant, affecting any WordPress installation where the specific 'Remove query strings from static resources' setting is enabled.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the W3 Total Cache plugin to the latest version immediately to remediate the flaw addressed in CVE-2026-87920.\u003c/li\u003e\n\u003cli\u003eUntil patching is possible, disable the 'Remove query strings from static resources' setting in the W3 Total Cache plugin configuration to mitigate the exploitation vector.\u003c/li\u003e\n\u003cli\u003eImplement a robust Content Security Policy (CSP) to limit the impact of potential XSS attacks by restricting the sources from which scripts can be executed.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T10:24:08Z","date_published":"2026-10-02T10:24:08Z","id":"https://feed.craftedsignal.io/briefs/2026-10-w3-total-cache-xss/","summary":"The W3 Total Cache plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-87920, allowing unauthenticated attackers to execute arbitrary web scripts via flawed Output-Buffer Regex rewriting.","title":"Stored Cross-Site Scripting in W3 Total Cache","url":"https://feed.craftedsignal.io/briefs/2026-10-w3-total-cache-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - W3 Total Cache (\u003c= 2.10.6)","version":"https://jsonfeed.org/version/1.1"}