9.0
CRITICAL CVSS 3.1
CVE-2025-9501
W3 Total Cache < 2.8.13 - Unauthenticated Command Injection
Description

The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.

INFO

Published Date :

Nov. 17, 2025, 6:15 a.m.

Last Modified :

Nov. 18, 2025, 2:06 p.m.

Remotely Exploit :

Yes !
Affected Products

The following products are affected by CVE-2025-9501 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 CRITICAL 134c704f-9b21-4f2e-91b3-4a467353bcc0
Solution
Update W3 Total Cache to version 2.8.13 or later to fix command injection.
  • Update W3 Total Cache plugin to version 2.8.13.
  • Apply necessary security patches for WordPress.
  • Review comment functionality for malicious inputs.
Public PoC/Exploit Available at Github

CVE-2025-9501 has a 1 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2025-9501.

URL Resource
https://wpscan.com/vulnerability/6697a2c9-63ae-42f0-8931-f2e5d67d45ae/
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2025-9501 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2025-9501 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

爬取secwiki和xuanwu.github.io/sec.today,分析安全信息站点、安全趋势、提取安全工作者账号(twitter,weixin,github等)

Python HTML

Updated: 1 week, 6 days ago
1386 stars 234 fork 234 watcher
Born at : Feb. 19, 2019, 10:24 a.m. This repo has been linked 12 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2025-9501 vulnerability anywhere in the article.

  • CybersecurityNews
NVIDIA’s Isaac-GROOT Robotics Platform Vulnerability Let Attackers Inject Malicious Codes

NVIDIA has disclosed two critical code injection vulnerabilities affecting its Isaac-GR00T robotics platform. The vulnerabilities, tracked as CVE-2025-33183 and CVE-2025-33184, exist within Python com ... Read more

Published Date: Nov 25, 2025 (1 week, 6 days ago)
  • CybersecurityNews
PoC released for W3 Total Cache Vulnerability that Exposes 1+ Million Websites to RCE Attacks

A proof-of-concept exploit has been publicly released for CVE-2025-9501, a critical, unauthenticated command-injection vulnerability affecting W3 Total Cache, one of WordPress’s most widely deployed c ... Read more

Published Date: Nov 24, 2025 (2 weeks ago)
  • BleepingComputer
W3 Total Cache WordPress plugin vulnerable to PHP command injection

A critical flaw in the W3 Total Cache (W3TC) WordPress plugin can be exploited to run PHP commands on the server by posting a comment that contains a malicious payload. The vulnerability, tracked as C ... Read more

Published Date: Nov 19, 2025 (2 weeks, 5 days ago)
  • The Cyber Express
50,000 CCTVs Hacked in India: Intimate Hospital Footage Sold Online

A disturbing case of hacking CCTV systems in India has exposed a widespread cybercrime racket through which intimate videos from a maternity ward were stolen and sold online. Police in Gujarat state s ... Read more

Published Date: Nov 19, 2025 (2 weeks, 5 days ago)
  • The Cyber Express
W3 Total Cache Vulnerability Puts Over One Million WordPress Sites at Risk

A severe security flaw has been discovered in the popular W3 Total Cache WordPress plugin, potentially exposing more than one million websites to remote code execution (RCE). The vulnerability, offici ... Read more

Published Date: Nov 18, 2025 (2 weeks, 5 days ago)
  • The Cyber Express
Fortinet Silent Patch Raises Concern Among Security Researchers

Fortinet may have silently patched an exploited zero-day vulnerability more than two weeks before officially disclosing the vulnerability. CVE-2025-64446 in Fortinet’s FortiWeb web application firewal ... Read more

Published Date: Nov 18, 2025 (2 weeks, 5 days ago)
  • CybersecurityNews
W3 Total Cache Command Injection Vulnerability Exposes 1 Million WordPress Sites to RCE Attacks

A critical command injection vulnerability has been discovered in the W3 Total Cache plugin, one of WordPress’s most popular caching solutions used by approximately 1 million websites. The vulnerabili ... Read more

Published Date: Nov 18, 2025 (2 weeks, 6 days ago)

The following table lists the changes that have been made to the CVE-2025-9501 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Nov. 17, 2025

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • New CVE Received by [email protected]

    Nov. 17, 2025

    Action Type Old Value New Value
    Added Description The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.
    Added Reference https://wpscan.com/vulnerability/6697a2c9-63ae-42f0-8931-f2e5d67d45ae/
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
Vulnerability Scoring Details
Base CVSS Score: 9.0
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact