Sceawere
Vulnerability Detail
CVE-2026-87920UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
W3 Total Cache Stored XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 13h ago
- Vendor
- boldgrid
- Product
- W3 Total Cache
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, and including, 2.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the 'Remove query strings from static resources' option is enabled in W3 Total Cache, as mutate_url() must strip the '?' delimiter and everything following it — including the closing quote of the outer attribute — to break the attribute boundary.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-02T10:17:08.857Z",
"pubdate": "2026-10-02T10:17:08.857Z",
"executiveSummary": "The W3 Total Cache plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability, allowing unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's session.\nThis vulnerability exists in versions up to and including 2.10.6 and is contingent upon the activation of the 'Remove query strings from static resources' setting.\nThe flaw stems from insufficient input sanitization and output escaping within the plugin's output-buffer regex rewrite mechanism.\nBy manipulating specific URL patterns, an attacker can break HTML attribute boundaries, facilitating the injection of malicious scripts.\nThe impact is significant, as it enables attackers to perform unauthorized actions on behalf of users, steal session tokens, or redirect traffic when the injected content is rendered in a browser.\nSuccessful exploitation is accessible to unauthenticated remote attackers, posing a high risk to the integrity and confidentiality of the WordPress installation.",
"technicalDetails": "The root cause of the vulnerability lies in the improper processing of cached output buffers within the W3 Total Cache plugin. Specifically, the vulnerability resides within the regex-based rewrite logic used for resource optimization when the 'Remove query strings from static resources' feature is enabled.\nThe core issue involves the mutate_url() function, which is designed to strip query parameters (starting with the '?' character) from static resource URLs to improve caching efficiency. When processing malicious content—typically embedded within comment fields or other user-supplied input—the regex engine fails to correctly account for attribute delimiters.\nAn attacker can craft a payload containing a URL that includes a '?' character followed by a closing quote and additional malicious attributes. Because the mutate_url() function aggressively strips the '?' delimiter and subsequent characters, it inadvertently removes the legitimate closing quote of an HTML attribute. This effectively breaks the attribute boundary, allowing the attacker to escape the intended HTML tag and inject arbitrary JavaScript attributes (such as 'onerror' or 'onload').\nThe attack flow follows these steps: 1) The attacker submits a specially crafted comment or input containing a payload designed to exploit the regex rewrite logic. 2) The WordPress system stores this input as part of the post/comment content. 3) W3 Total Cache processes the page content through its output buffer. 4) The mutate_url() function encounters the malicious URL pattern. 5) By stripping the '?' delimiter and the subsequent closing quote, the function inadvertently closes the current tag and opens a new context for script injection. 6) When a legitimate user, including administrators, views the page, the browser interprets the manipulated HTML and executes the injected script.\nBecause the payload is stored within the database and served as part of the page content, the vulnerability is classified as Stored XSS. It requires no authentication to reach the input vector, and the execution occurs within the victim's browser, bypassing standard same-origin policy protections within the affected site context.\nAffected systems are restricted to WordPress installations utilizing W3 Total Cache versions up to and including 2.10.6, provided the aforementioned caching configuration is active."
}