Sceawere

Vulnerability Detail

CVE-2026-107321UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

W3 Total Cache Arbitrary File Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
8h ago
Vendor
Unknown
Product
W3 Total Cache
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The W3 Total Cache WordPress plugin before 2.10.6 does not confine a media-import file copy to the document root, nor enforce an effective file-type restriction on it, allowing users with the Author role or higher to plant content that, once an administrator runs the import, copies an arbitrary server-readable file into a publicly served directory, exposing it to unauthenticated retrieval.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-10T06:16:41.017Z",
  "pubdate": "2026-10-10T06:16:41.017Z",
  "executiveSummary": "The W3 Total Cache WordPress plugin contains an Arbitrary File Disclosure vulnerability due to insufficient validation of file paths and types during the media-import process.\nThe vulnerability allows authenticated users with Author-level privileges or higher to manipulate the import functionality to copy sensitive, server-readable files into a publicly accessible directory.\nOnce the file is relocated, it becomes available for unauthenticated retrieval by remote attackers, potentially leading to the disclosure of sensitive configuration files, environment variables, or other system secrets.\nThis vulnerability impacts all versions of W3 Total Cache prior to 2.10.6.\nSuccessful exploitation requires the attacker to possess authenticated access to the WordPress dashboard with at least Author-level permissions and relies on an administrator subsequently triggering the import process.\nGiven the ability to extract critical system files, the risk implications are high, as the vulnerability may serve as a precursor to full site compromise or privilege escalation.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper sanitization and confinement of file paths within the plugin's media-import functionality. The application fails to restrict file copy operations to the designated document root and neglects to enforce rigorous file-type validation during the import procedure.\nThe attack flow begins with an authenticated attacker possessing Author-level permissions or higher. The attacker leverages the plugin's media-import feature to define a source path for a file that the web server process has read access to. Because the input parameters are not adequately validated against a whitelist of permitted directories or file types, the attacker can supply an arbitrary path pointing to sensitive system files (e.g., wp-config.php or internal system logs).\nUpon submission, the malicious import request is queued for processing. When an administrator interacts with the import feature, the application executes the file copy operation without verifying that the source file is intended for public consumption. Consequently, the application copies the target file from its secure, non-public location into a publicly served directory within the web root.\nOnce the copy operation completes, the sensitive file is indexed and exposed through the web server's public-facing directory. An unauthenticated attacker can subsequently retrieve the target file by crafting a direct HTTP request to the file's new location. The vulnerability effectively bypasses filesystem permissions that would normally prevent external access to configuration or system data.\nThis behavior facilitates the exfiltration of sensitive information, such as database credentials, secret keys, and application-specific logic. The lack of validation on both the source and target path parameters represents a critical failure in secure file handling practices within the WordPress plugin ecosystem. Because the plugin processes the file copy as an authenticated action, it evades typical security filters that might otherwise block direct access to sensitive system files, making the exploit highly effective for obtaining post-exploitation intelligence necessary for further attacks."
}
CVE-2026-107321: W3 Total Cache Arbitrary File Disclosure (MEDIUM Severity, CVSS: 5.4) | Sceawere