CVE-2026-27384: WordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerability
Published Mar 5, 2026
·Updated
Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects W3 Total Cache: from n/a through <= 2.9.1.
Affected Software
2 affected components
BoldGrid W3 Total Cache<=2.9.1
wordpress/w3-total-cache<=2.9.1
Event History
Mar 5, 2026
CVE Published
via MITRE·05:53 AM
Data Sourced
via MITRE·05:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27384?
CVE-2026-27384 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2026-27384?
To fix CVE-2026-27384, update the W3 Total Cache plugin to a version higher than 2.9.1.
3
Who is affected by CVE-2026-27384?
CVE-2026-27384 affects users of the W3 Total Cache plugin version 2.9.1 or lower on WordPress.
4
What kind of vulnerability is CVE-2026-27384?
CVE-2026-27384 is an arbitrary code execution vulnerability caused by improper validation of specified input.
5
What plugin does CVE-2026-27384 pertain to?
CVE-2026-27384 pertains to the W3 Total Cache plugin for WordPress.