CVE-2026-66695 MEDIUM

CVE-2026-66695: WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability

Vendor Boldgrid
Product W3 Total Cache
Weakness CWE-35
Published August 6, 2026
Last update August 6, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.

Explanation of Vulnerability in Simple Terms

02Summary

W3 Total Cache versions up to 2.10.2 contain a path traversal vulnerability that allows attackers to modify files on the site without authentication. By crafting requests with multiple leading dots in file paths, an attacker can bypass directory restrictions and alter site content or configuration. Update immediately to a version newer than 2.10.2.

What an attacker can do

03Attacker Capabilities

Modify or delete files on the site without logging in.

Potential impact on your site

04Site Impact

Site files and configuration can be altered or deleted by remote attackers, potentially breaking functionality or injecting malicious content.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated

Related vulnerabilities

08Related CVE