CVE-2026-78438: stored cross-site scripting in boldgrid W3 Total Cache

Attackers with no account access can store malicious JavaScript that later runs in visitors’ browsers on sites using the W3 Total Cache WordPress plugin. This is CVE-2026-78438. The vulnerability exists in W3 Total Cache 2.x up to and including 2.10.5. Successful exploitation requires the plugin’s lazy-load feature to be active with the option that processes background images enabled, and the attacker’s crafted comment must be accepted by a moderator so the payload is served to users.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.2HIGH
EPSS
0.00498
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Prioritise mitigation because there is no vendor fix for affected releases and the flaw allows unauthenticated script injection that executes for site visitors once a comment is approved.

What is CVE-2026-78438?

Attackers with no account access can store malicious JavaScript that later runs in visitors’ browsers on sites using the W3 Total Cache WordPress plugin. This is CVE-2026-78438. The vulnerability exists in W3 Total Cache 2.x up to and including 2.10.5. Successful exploitation requires the plugin’s lazy-load feature to be active with the option that processes background images enabled, and the attacker’s crafted comment must be accepted by a moderator so the payload is served to users. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Which versions of boldgrid W3 Total Cache are affected?

BRANCHAFFECTEDFIXED
2.x2.10.5 and earlier

Is CVE-2026-78438 being exploited?

There are no public reports of exploitation or public exploit code for CVE-2026-78438 as of 2026-09-30.

How to fix CVE-2026-78438

  1. Disable the Lazy Load Images feature or turn off the "Process background images" option in W3 Total Cache until a patch is available.
  2. Harden comment controls: block untrusted HTML in comments, disable anonymous posting, or require stricter moderation before publishing.
  3. Monitor web logs and page content for unexpected script tags and review recent approved comments for injected payloads.
  4. Follow vendor advisories and apply an official update when the developer releases a fixed version.

Frequently asked questions

Is CVE-2026-78438 being actively exploited?

There are no public reports of active exploitation of CVE-2026-78438 as of 2026-09-30.

Which W3 Total Cache versions are affected by CVE-2026-78438?

W3 Total Cache 2.x releases up to and including 2.10.5 are affected by CVE-2026-78438.

Is there a patch for CVE-2026-78438?

No patch was available for the affected W3 Total Cache releases as of 2026-09-30.

Does CVE-2026-78438 require authentication?

An attacker can submit the malicious content without authenticating, but the injected comment must be approved by a moderator and the specific lazy-load background image processing option must be enabled for the payload to execute.

References