All verified exploits

CVE-2026-5032 Security Token Exposure via User-Agent Bypass

Deterministic high WordPress Added cve-verified-cve-2026-5032

Detects WordPress instances running W3 Total Cache plugin version 2.9.3 or earlier, where the output buffering pipeline is bypassed when the User-Agent header contains 'W3 Total Cache'. This causes raw mfunc/mclude HTML comments — including the W3TC_DYNAMIC_SECURITY token — to appear in the page source. That token is the only thing protecting a feature that passes PHP code to eval(), enabling unauthenticated remote code execution when chained with mfunc injection.

Related WordPress exploits

Is your app exploitable through CVE-2026-5032?

Scan your domain free