CVE-2025-9501: Unknown w3 Total Cache

Critical severity, CVSS 9.0. EPSS: 22.6% chance of exploitation in the next 30 days.

The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.

Affected products

  • Unknown w3 Total Cache: before 2.8.13 (fixed in 2.8.13)

Published 2025-11-17. Last modified 2026-06-17.