BU haber ne zaman çıktı bilmiyorum ama 29.12.2012 güncellemesinde bahsedilen açığı kapattıklarını iddia ediyorlar...
0.9.2.5
Fixed security issue that can occur if using database caching to disk. If using database caching to disk with a web server with directory listing or web accessible wp-content/w3tc/dbcache/* directories. This patch works for all hosting environments / types where PHP is properly configured, i.e. .htaccess modifications (or other web server configuration changes) are not necessary to ensure proper security. Empty the database cache after performing the update if you use database caching to disk.