CVE-2025-9501: Unknown w3 Total Cache
Critical severity, CVSS 9.0. EPSS: 22.6% chance of exploitation in the next 30 days.
The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.
Affected products
- Unknown w3 Total Cache: before 2.8.13 (fixed in 2.8.13)
Published 2025-11-17. Last modified 2026-06-17.