CVE-2026-9282

HIGH EXPLOITED NUCLEI

W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-9282 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including incogbyte. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated arbitrary file read vulnerability in W3 Total Cache <= 2.9.4 via the `f_array` parameter in the minify request handler. The PoC reads sensitive files like `wp-config.php` by leveraging improper input validation in manual-mode minify group processing.

Description

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires enabling manual minify mode and supplying a manual-format minify filename so that the hash is empty and the f_array[] entries are not overwritten before reaching setupSources().

Exploits (1)

github WORKING POC 3 stars
by incogbyte · pythonpoc
https://github.com/incogbyte/wp-cve-exploits/tree/main/CVE-2026-9282

This exploit demonstrates an unauthenticated arbitrary file read vulnerability in W3 Total Cache <= 2.9.4 via the `f_array` parameter in the minify request handler. The PoC reads sensitive files like `wp-config.php` by leveraging improper input validation in manual-mode minify group processing.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: W3 Total Cache plugin for WordPress, versions <= 2.9.4
No auth needed
Prerequisites: Target must have at least one 'manual' minify group configured · Attacker must know or guess a valid theme/location key from the target's minify group configuration
mistral-large-3 · analyzed Jul 14, 2026 Full analysis →

Nuclei Templates (1)

W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read
HIGHVERIFIEDby 0x_Akoko
Shodan: http.html:"w3-total-cache"
FOFA: body="/wp-content/plugins/w3-total-cache/"

Scores

CVSS v3 7.5
EPSS 0.0277
EPSS Percentile 84.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2026-07-14
CWE
CWE-22
Status published
Products (1)
boldgrid/W3 Total Cache < 2.9.4
Published Jul 11, 2026
Tracked Since Jul 11, 2026