CVE Watchtower


← Back to CVE List

CVE-2025-9501NVD

Vulnerability Summary

The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.
Severity Level
UNKNOWN
Published Date
Nov 17, 2025
Last Modified
Nov 17, 2025
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
N/A