BoldGrid Vulnerabilities and Affected Products
Vulnerabilities associated with w3_total_cache.
Products
Clear product- W3 Total Cache14 vulnerabilities
- Client Invoicing by Sprout Invoices8 vulnerabilities
- Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid6 vulnerabilities
- Post and Page Builder by BoldGrid5 vulnerabilities
- Post and Page Builder by BoldGrid – Visual Drag and Drop Editor5 vulnerabilities
- Sprout Clients4 vulnerabilities
- BoldGrid Easy SEO – Simple and Effective SEO2 vulnerabilities
- Total Upkeep2 vulnerabilities
- total_upkeep2 vulnerabilities
- weForms2 vulnerabilities
- weForms – Easy Drag & Drop Contact Form Builder For WordPress2 vulnerabilities
- Help Scout1 vulnerability
- w3_total_cache1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-9282HIGH | W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' ParameterThe W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires enabling manual minify mode and supplying a manual-format minify filename so that the hash is empty and the f_array[] entries are not overwritten before reaching setupSources(). | CVSS7.5v3.1 | EPSS2.77% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |