Impact
The vulnerability allows an unauthenticated attacker to trigger arbitrary code execution on the host server when a WordPress site runs the W3 Total Cache plugin versions 2.9.4 and earlier. By sending crafted input to the plugin, an attacker can execute arbitrary commands, which may lead to a complete compromise of the affected website and its underlying infrastructure. This weakness is classified as CWE‑1284, representing an input validation flaw that permits arbitrary code execution.
Affected Systems
The vulnerability affects the BoldGrid W3 Total Cache plugin for WordPress, version 2.9.4 and earlier, which may be installed on any WordPress site. Administrators should confirm the current plugin version and upgrade to at least.0 as soon as possible.
Risk and Exploitability
The CVSS score of 9 flags this vulnerability, and the EPSS score of < 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated network request to the WordPress site that triggers the plugin’s code path, meaning anyone with network access to the website can potentially exploit the flaw without authentication. The impact of exploitation is severe, as it affords complete control of the application server.
OpenCVE Enrichment