← Back to browse · API

CVE-2025-9501

Severity
CRITICAL
CVSS
9.0
EPSS
0.20473
Risk score
43.17
CISA KEV
No
PoC
No
Published
2025-11-17
Modified
2025-11-17
First seen
2026-08-07
Aliases
EUVD-2025-197764, GHSA-WX46-PC78-PQHQ
Products
boldgrid:W3 Total Cache 0 <2.8.13
Sources
euvd EUVD-2025-197764

Description

The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.

References