EIP-2026-114180

PRE-CVE

WordPress Plugin W3 Total Cache - 'admin.php' Cross-Site Request Forgery

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114180. PoCs published by Voxel@Night.

AI-analyzed exploit summary The provided text describes a CSRF vulnerability in the W3 Total Cache WordPress plugin, allowing attackers to perform unauthorized actions in the context of a logged-in user. The exploit URL demonstrates the vulnerability by enabling the 'edge' mode without proper CSRF protection.

Description

WordPress Plugin W3 Total Cache - 'admin.php' Cross-Site Request Forgery

Exploits (1)

exploitdb WRITEUP VERIFIED
by Voxel@Night · textwebappsphp
https://www.exploit-db.com/exploits/39304

The provided text describes a CSRF vulnerability in the W3 Total Cache WordPress plugin, allowing attackers to perform unauthorized actions in the context of a logged-in user. The exploit URL demonstrates the vulnerability by enabling the 'edge' mode without proper CSRF protection.

Classification
Writeup 80%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: W3 Total Cache plugin for WordPress 0.9.4
Auth required
Prerequisites: Victim must be logged into WordPress admin panel · Attacker must lure victim to crafted URL
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026