CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-18051

criticalCVSS 10covered by 1 sourcefirst seen 2026-08-19
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.

⚡ Watch CVE-2026-18051

Get an email if CVE-2026-18051 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-18051

CVE.org record

Embed the live status

CVE-2026-18051 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-18051 status](https://www.csirts.com/badge/CVE-2026-18051)](https://www.csirts.com/cve/CVE-2026-18051)