W3 Total Cache < 2.8.13 - Unauthenticated Command Injection Print

  • 0

WordPress Plugin Vulnerabilities

Description

The plugin is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.

Proof of Concept

The PoC will be displayed on November 24, 2025, to give users the time to update.

 

Affects Plugins

w3-total-cache  Fixed in 2.8.13
 

References

CVE

CVE-2025-9501

Classification

Type COMMAND INJECTION
OWASP top 10
A1: Injection
CWE CWE-78
CVSS 9.0 (critical)

Miscellaneous

Original Researcher
wcraft
Submitter
wcraft
Verified
Yes
WPVDB ID
6697a2c9-63ae-42f0-8931-f2e5d67d45ae
 

Timeline

Publicly Published
2025-10-27 (about 26 days ago)
Added
2025-10-27 (about 25 days ago)
Last Updated
2025-10-27 (about 25 days ago)
 

 

 


Was this answer helpful?

« Back