11 versions
W3 Total Cache Pro history.
Every release of W3 Total Cache Pro is archived here with its changelog, file size, and security scan result. Use the archive to roll back to a stable release or audit what changed between updates.
10 of 11 releases scanned clean
v2.10.6Latest
September 11, 20269.3 MBScanned
Fixed
- Database Cluster: Restore placeholder unescape so admin searches with wildcards match
- Settings: Restrict POST updates to keys owned by the active admin page
- Licensing: Limit plugin type updates to the license path
- Image Converter: Require administrator capability for convert and submit
- Config import: Validate structure before applying
- Role cookies: Stop honoring legacy names unless explicitly enabled
- Minify: Validate precache URLs before outbound fetch
- URL constants: Apply host allowlists to overrides
- Minify: Validate Java minifier JAR paths before invocation
- Diagnostics: Extend log redaction across remaining formats
- Reverse proxy: Apply forwarded client IP and scheme headers only from trusted proxies
- CDN: Limit Media Library import to static assets
- CDN: Render admin server responses as text
- CDN: Use saved settings for Test
- CDN: Scope CORS headers to font resources
- Browser Cache: Normalize rewrite rule rendering
- Support: Reduce client data sent from the Support page
- Forums: Normalize API client responses
- Lazy Load: Match background styles as top-level attributes only
- Admin: Align request validation across notice, extension, setup, CDN, and minify flows
Added
- Page Cache: Add w3tc_pgcache_rules_required filter to skip writing rewrite rules
Improved
- Bunny CDN and Redis: Enable verified TLS by default
v2.10.2Unavailable
July 21, 20269.2 MBScanned
Fixed
- Disk cache: Restore file-locking writes on PHP 8+
- Apache: Limit Options -MultiViews in page cache rules to compatibility mode
- Page Cache: Skip storing redirect responses
v2.10.1Unavailable
July 10, 20269.2 MBScanned
Fixed
- General Settings: "The link you followed has expired" when emptying all caches
- Redis/Memcached/CDN: Restore connection handling after 2.10.0 at-rest credential encryption
- At-rest credentials: Defer encryption until WordPress salts are available
- Always Cached: Queue regeneration on nginx with Disk: Enhanced page cache
- mfunc: Render unrecognized dynamic-fragment tags as empty output
- Apache: Remove Options -MultiViews from root .htaccess (HTTP 500 on restrictive AllowOverride)
- Multisite: Admin page links in network admin
v2.10.0Unavailable
June 24, 20269.1 MBScanned
* Security: Hardened authorization, capability, and request-verification (nonce/CSRF) checks across admin and AJAX endpoints
* Security: Improved input validation and output escaping to prevent cross-site scripting (XSS)
* Security: Strengthened protections against code, command, and file-inclusion injection
* Security: Hardened processing of dynamic and cached content, including data serialization
* Security: Restricted outbound server-side requests to mitigate server-side request forgery (SSRF)
* Security: Restricted configuration changes to prevent unauthorized modification
* Security: Improved handling of stored credentials, cookies, and generated server-configuration files
* Security: Reduced potential information disclosure and improved security logging
v2.9.2Unavailable
March 6, 20269.2 MBScanned
Fixed
- Patch broken access control for Image Service AJAX operations
- mfunc dynamic output buffering fatal error causing blank pages
- Patch mfunc security vulnerability
v2.9.1Unavailable
January 16, 20269.2 MBScanned
Fixed
- Image Converter: Reset request when status is 404
- Image Converter: Better handling of separate format requests
- Image Converter: UI/JS changes
- Config caching/saving issue
v2.9.0Unavailable
January 15, 20269.2 MBUnknown
Added
- Next-Gen AVIF image conversion (Pro)
- Added notices for some billing issues
Fixed
- Bunny CDN purge section
- New Relic API
- Nginx + Memcached Unix socket compatability
Improved
- Setup Guide Wizard and test improvements
- WebP Converter renamed to Image Converter
Why archive
Sometimes the latest release isn't the one you need. The archive lets you pin W3 Total Cache Pro to a known-good version, or roll back while a bug is investigated. Every release stays scanned and reachable.