Impact
The vulnerability is a stored XSS flaw in the W3 Total Cache WordPress plugin caused by insufficient sanitization and escaping of comment content processed by the output‑buffer regex rewrite. Unauthenticated users can insert malicious scripts into comments, and those scripts are stored and executed every time the comment is rendered on a page. The flaw is the only known way for an attacker to inject code under the affected plugin configuration.
Affected Systems
The issue affects the BoldGrid W3 Total Cache plugin for WordPress versions up to and including 2.10.6. Any WordPress site running those vulnerable releases is at risk.
Risk and Exploitability
The CVSS score of 7.2 indicates a high impact with potential for widespread compromise of visitor browsers once the comment is displayed. Although the EPSS score is not available, the flaw can be exploited by unauthenticated users due to the plugin setting 'Remove query strings from static resources' being enabled; this option triggers the regex rewrite that allows the attribute boundary to be broken. The vulnerability is not listed in CISA KEV, but an attacker can still easily insert malicious payloads in free or public sites.
OpenCVE Enrichment