Detects WordPress instances running W3 Total Cache plugin version 2.9.3 or earlier, where the output buffering pipeline is bypassed when the User-Agent header contains 'W3 Total Cache'. This causes raw mfunc/mclude HTML comments — including the W3TC_DYNAMIC_SECURITY token — to appear in the page source. That token is the only thing protecting a feature that passes PHP code to eval(), enabling unauthenticated remote code execution when chained with mfunc injection.
Is your app exploitable through CVE-2026-5032?
Scan your domain free