Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects W3 Total Cache: from n/a through <= 2.9.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone Python exploit/scanner for CVE-2026-27384 affecting the WordPress W3 Total Cache plugin <= 2.9.1. The repo is minimal: one Python script (CVE-2026-27384.py) and one README. The Python file is the operational component and appears to support both single-target exploitation and bulk scanning, with CLI argument handling, threaded execution, progress bars, session creation, result saving, optional proxy support, timeout handling, and verbose output. Visible code paths show functions such as main(), make_session(), exploit_single(), bulk_scan(), and save_results() being used, indicating a practical scanner/exploit rather than a simple proof-of-concept. The exploit’s core capability is unauthenticated web-based RCE. According to the README and script naming/usage, it abuses W3 Total Cache Dynamic Fragment Caching by injecting crafted mfunc payloads into WordPress comments, then triggering cached page processing so the plugin evaluates attacker-controlled PHP. The README describes the vulnerability chain in detail: unsafe regex construction around W3TC_DYNAMIC_SECURITY, mismatch between stripping and execution regexes (\s+ vs \s*), and insufficient token validation. This allows a payload such as an mfunc block containing shell_exec() to survive sanitization and later be executed via eval(). Operationally, the tool appears capable of: detecting W3TC presence, locating commentable posts/pages automatically, submitting exploit content, re-requesting pages to trigger cache processing, executing attacker-provided commands, and scanning multiple targets concurrently. The README also documents modes named auto, exploit, shell, and detect, though only part of the Python source is visible due to truncation. The script is therefore more than a detector: it is an active exploitation utility with command execution support. No hardcoded victim infrastructure, C2, or exfiltration endpoints are present in the provided content. The exploit is target-driven and accepts user-supplied URLs. Fingerprintable artifacts are mostly target-side identifiers and references: the W3TC_DYNAMIC_SECURITY constant, mfunc/mclude tags, and wp-config.php as the configuration location discussed in the README. Overall, this is a credible operational exploit/scanner for a WordPress plugin RCE, intended to automate discovery and exploitation of vulnerable W3 Total Cache deployments.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.