DIRAS TAKE
Prioritise mitigation because there is no vendor fix for affected releases and the flaw allows unauthenticated script injection that executes for site visitors once a comment is approved.
What is CVE-2026-78438?
Attackers with no account access can store malicious JavaScript that later runs in visitors’ browsers on sites using the W3 Total Cache WordPress plugin. This is CVE-2026-78438. The vulnerability exists in W3 Total Cache 2.x up to and including 2.10.5. Successful exploitation requires the plugin’s lazy-load feature to be active with the option that processes background images enabled, and the attacker’s crafted comment must be accepted by a moderator so the payload is served to users. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of boldgrid W3 Total Cache are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2.x | 2.10.5 and earlier |
Is CVE-2026-78438 being exploited?
There are no public reports of exploitation or public exploit code for CVE-2026-78438 as of 2026-09-30.
How to fix CVE-2026-78438
- Disable the Lazy Load Images feature or turn off the "Process background images" option in W3 Total Cache until a patch is available.
- Harden comment controls: block untrusted HTML in comments, disable anonymous posting, or require stricter moderation before publishing.
- Monitor web logs and page content for unexpected script tags and review recent approved comments for injected payloads.
- Follow vendor advisories and apply an official update when the developer releases a fixed version.
Frequently asked questions
Is CVE-2026-78438 being actively exploited?
There are no public reports of active exploitation of CVE-2026-78438 as of 2026-09-30.
Which W3 Total Cache versions are affected by CVE-2026-78438?
W3 Total Cache 2.x releases up to and including 2.10.5 are affected by CVE-2026-78438.
Is there a patch for CVE-2026-78438?
No patch was available for the affected W3 Total Cache releases as of 2026-09-30.
Does CVE-2026-78438 require authentication?
An attacker can submit the malicious content without authenticating, but the injected comment must be approved by a moderator and the specific lazy-load background image processing option must be enabled for the payload to execute.
References
- nvd.nist.gov/vuln/detail/CVE-2026-78438
- cve.org/CVERecord?id=CVE-2026-78438
- wordfence.com/threat-intel/vulnerabilities/id/5580ad05-af50-4899-9cbf-39ad8000eb6a?source=cve
- plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Mutator.php#L293
- plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Mutator.php#L255
- plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Mutator.php#L91
- plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Plugin.php#L87
- plugins.trac.wordpress.org/changeset?reponame=&new=3680101%40w3-total-cache%2Ftags%2F2.10.6&old=3653442%40w3-total-cache%2Ftags%2F2.10.5
- plugins.trac.wordpress.org/changeset?old_path=%2Fw3-total-cache/tags/2.10.5&new_path=%2Fw3-total-cache/tags/2.10.6
- plugins.trac.wordpress.org/changeset/3680101/w3-total-cache/tags/2.10.6/UserExperience_LazyLoad_Mutator.php
- All boldgrid CVEs on CVE Radar
- CVEs published in September 2026