The W3TC version 0.9.4.1 support page has a XSS vulnerability. This plugin denies access to ALL users to the W3TC support page, gives you time to change plugins.
Install: Either: upload w3tc_deny_support.php in your root/wp-content/mu-plugins folder. All done. OR ... go to your dashboard, upload w3tc_deny_support.php.zip as new plugin and ACTIVATE. All done.
This plugin was featured in https://www.managedwphosting.nl/2016/09/w3-total-cache-vulnerability-wij-hebben-een-fix/