{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/w3-total-cache/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-18109"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["W3 Total Cache"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["BoldGrid"],"content_html":"\u003cp\u003eThe W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping when processing comment author names. This vulnerability, identified as CVE-2026-18109, affects all versions up to and including 2.10.3. The flaw is specifically triggered when the 'Lazy Load Images' feature is enabled. The vulnerability exists because the plugin's LazyLoad mutator performs unsafe re-emission of data during the img tag rewriting process. An unauthenticated attacker can supply a crafted string as an author name in a comment, which is then stored by the application and injected into pages where images are lazy-loaded. When an unsuspecting user, such as an administrator, views a page containing the injected comment, the malicious script executes within their browser context, potentially leading to session hijacking, unauthorized actions, or site redirection.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress site using W3 Total Cache with the 'Lazy Load Images' feature enabled.\u003c/li\u003e\n\u003cli\u003eAttacker submits a new comment on a public post, populating the 'Author Name' field with a payload containing malicious JavaScript (e.g., \u0026lt;script\u0026gt;alert(1)\u0026lt;/script\u0026gt;).\u003c/li\u003e\n\u003cli\u003eThe WordPress application accepts the comment and stores the malicious payload in the 'comment_author' database column.\u003c/li\u003e\n\u003cli\u003eThe W3 Total Cache plugin detects the comment during page rendering.\u003c/li\u003e\n\u003cli\u003eThe plugin's LazyLoad mutator attempts to process images on the page and incorrectly re-emits the stored 'comment_author' string within an HTML attribute or tag content.\u003c/li\u003e\n\u003cli\u003eThe injected script is rendered into the HTML of the page served to visitors.\u003c/li\u003e\n\u003cli\u003eA legitimate user (e.g., an administrator) navigates to the compromised page.\u003c/li\u003e\n\u003cli\u003eThe victim's browser executes the attacker-supplied script, resulting in potential account takeover or unauthorized operations.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated remote attackers to execute arbitrary web scripts in the browser of any user who views the affected content. This poses a significant risk for administrative account compromise, as administrators frequently view comment moderation queues or pages where comments appear. If successful, this can lead to full site takeover, configuration changes, or the installation of malicious plugins.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the W3 Total Cache plugin to a version beyond 2.10.3 immediately to patch CVE-2026-18109.\u003c/li\u003e\n\u003cli\u003eDisable the 'Lazy Load Images' feature in W3 Total Cache until the update can be applied to mitigate the specific attack vector.\u003c/li\u003e\n\u003cli\u003eAudit existing comments on WordPress sites for anomalous characters or script tags in the author name field.\u003c/li\u003e\n\u003cli\u003eEnable Content Security Policy (CSP) headers to restrict the execution of inline scripts and unauthorized external resources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T04:06:10Z","date_published":"2026-08-14T04:06:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-w3-total-cache-xss/","summary":"The W3 Total Cache plugin for WordPress versions up to 2.10.3 is vulnerable to Stored Cross-Site Scripting when the Lazy Load Images feature is enabled, allowing unauthenticated attackers to inject malicious scripts via comment author names.","title":"Stored Cross-Site Scripting in W3 Total Cache","url":"https://feed.craftedsignal.io/briefs/2026-08-w3-total-cache-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - W3 Total Cache","version":"https://jsonfeed.org/version/1.1"}