CVE-2026-9282 is a high-severity Directory Traversal vulnerability in the W3 Total Cache WordPress plugin (by BoldGrid), affecting all versions up to and including 2.9.4. The flaw resides in the setupSources function and allows unauthenticated remote attackers to read the contents of arbitrary files on the server, with a CVSS v3.1 base score of 7.5 (HIGH). With over 900,000 active installations, the plugin represents a significant attack surface across the WordPress ecosystem.
