A serious vulnerability in the popular WordPress plugin W3 Total Cache (W3TC) has raised alarm in the security community. The flaw allows attackers to execute arbitrary PHP code on the server simply by posting a malicious comment. The vulnerability is tracked as CVE-2025-9501 and affects all versions of the plugin prior to 2.8.13.

With over a million active installations, W3 Total Cache is one of the most widely used speed optimization tools in the WordPress ecosystem — which makes the vulnerability even more concerning.
What is CVE-2025-9501 and why is it considered so dangerous?
The issue is characterized as an unauthorized command injection, allowing an attacker to pass a malicious PHP command through an innocent-looking comment. The root of the issue is found in the _parse_dynamic_mfunc(), which is designed to process dynamic function calls stored in the cache.
See also: WhatsApp vulnerability exposed 3.5 billion phone numbers
According to WPScan, the well-known WordPress security team: “The plugin is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthorized users to execute PHP commands by submitting a comment with a malicious payload.”
If an attacker manages to exploit the vulnerability, they could even gain complete control of the website, since PHP commands are executed on the server without even needing to log in. This is a classic “site takeover” risk.
The update has been released — but many haven't installed it
The developer of W3 Total Cache released version 2.8.13 on October 20, fixing the issue. However, data from WordPress.org reveals something troubling: despite about 430,000 downloads of the new version, hundreds of thousands of websites appear to be using older — and vulnerable — versions.

This is not uncommon in WordPress. Many administrators either don't enable automatic updates or are simply slow to maintain their sites. However, in this case, the delay can prove disastrous.
Researchers prepare PoC publication – Time is running out
WPScan announced that it has already developed a proof-of-concept exploit (PoC), which it plans to publish on November 24.The reason for the delay is to give website owners time to proceed with the upgrade.
See also: Android: Reducing memory security vulnerabilities due to Rust
However, experience has shown that once a PoC becomes available:
- automated scans are launched,
- bots start to identify vulnerable targets,
- and mass attacks begin almost immediately.
In other words, we are talking about a race before Aeolus's bag opens.
What WordPress site administrators should do
Those using W3 Total Cache should take immediate action. The recommended actions are:
1. Installing version 2.8.13
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
It is the safest, recommended option. The update closes the security gap and protects the server from attacks.
2. Temporarily disable the plugin
If for any reason an upgrade cannot be made immediately — e.g. due to incompatibility or the need for staging tests — then disabling the plugin drastically reduces the risk.
3. Control and limit comments
Until the system is upgraded, administrators can:
- enable comment approval before publishing,
- disable comments altogether,
- or use plugins that filter out dangerous payloads.
None of these are absolute solutions, but they reduce the chances of exploitation.
See also: ASUS: Critical vulnerability in DSL series routers

Wider implications and what this incident shows
The W3TC case is yet another example of how vulnerable the WordPress ecosystem can become because of a single plugin. With over 60,000 plugins available, the attack surface is huge — and administrators should treat updates as mandatory “daily maintenance.”
At the same time, it brings to the fore an old security truth: caching plugins, because of the way they interact with the backend, are often high-risk points in the system.
The ability to perform dynamic operations through cached content is extremely useful, but it opens doors to serious exploits if not implemented securely.
CVE-2025-9501 is one of the most serious vulnerabilities we've seen in WordPress plugins recently, largely because of the simplicity with which it can be exploited. With a simple comment, a hacker can gain full access to the server.
Upgrading to W3 Total Cache 2.8.13 is not just a "good practice" — it is absolutely necessary to protect every WordPress site that uses the plugin.
Source: www.bleepingcomputer.com
