W3 Total Cache WordPress plugin vulnerable to PHP command injection
ID: d44a16f4-0bbe-5c9a-a336-d1c4a98efe10
STIX ID: report--d44a16f4-0bbe-5c9a-a336-d1c4a98efe10
Feed Name: Bleeping Computer
Threat Score
A critical unauthenticated command injection (CVE-2025-9501) in the W3 Total Cache WordPress plugin enables attackers to execute arbitrary PHP commands by submitting a crafted comment; a fix (v2.8.13) was released on October 20 but hundreds of thousands of sites may still be vulnerable and a public proof-of-concept exploit is due to be published, raising the risk of widespread compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
