HomeSecurityWordPress: Serious vulnerability in the W3 Total Cache plugin

WordPress: Serious vulnerability in W3 Total Cache plugin

A serious vulnerability in the popular WordPress plugin W3 Total Cache (W3TC) has raised alarm in the security community. The flaw allows attackers to execute arbitrary PHP code on the server simply by posting a malicious comment. The vulnerability is tracked as CVE-2025-9501 and affects all versions of the plugin prior to 2.8.13.

W3 Total Cache WordPress

With over a million active installations, W3 Total Cache is one of the most widely used speed optimization tools in the WordPress ecosystem — which makes the vulnerability even more concerning.

What is CVE-2025-9501 and why is it considered so dangerous?

The issue is characterized as an unauthorized command injection, allowing an attacker to pass a malicious PHP command through an innocent-looking comment. The root of the issue is found in the _parse_dynamic_mfunc(), which is designed to process dynamic function calls stored in the cache.

See also: WhatsApp vulnerability exposed 3.5 billion phone numbers

According to WPScan, the well-known WordPress security team: “The plugin is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthorized users to execute PHP commands by submitting a comment with a malicious payload.”

If an attacker manages to exploit the vulnerability, they could even gain complete control of the website, since PHP commands are executed on the server without even needing to log in. This is a classic “site takeover” risk.

The update has been released — but many haven't installed it

The developer of W3 Total Cache released version 2.8.13 on October 20, fixing the issue. However, data from WordPress.org reveals something troubling: despite about 430,000 downloads of the new version, hundreds of thousands of websites appear to be using older — and vulnerable — versions.

WordPress: Serious vulnerability in W3 Total Cache plugin

This is not uncommon in WordPress. Many administrators either don't enable automatic updates or are simply slow to maintain their sites. However, in this case, the delay can prove disastrous.

Researchers prepare PoC publication – Time is running out

WPScan announced that it has already developed a proof-of-concept exploit (PoC), which it plans to publish on November 24.The reason for the delay is to give website owners time to proceed with the upgrade.

See also: Android: Reducing memory security vulnerabilities due to Rust

However, experience has shown that once a PoC becomes available:

  • automated scans are launched,
  • bots start to identify vulnerable targets,
  • and mass attacks begin almost immediately.

In other words, we are talking about a race before Aeolus's bag opens.

What WordPress site administrators should do

Those using W3 Total Cache should take immediate action. The recommended actions are:

1. Installing version 2.8.13

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

It is the safest, recommended option. The update closes the security gap and protects the server from attacks.

2. Temporarily disable the plugin

If for any reason an upgrade cannot be made immediately — e.g. due to incompatibility or the need for staging tests — then disabling the plugin drastically reduces the risk.

3. Control and limit comments

Until the system is upgraded, administrators can:

  • enable comment approval before publishing,
  • disable comments altogether,
  • or use plugins that filter out dangerous payloads.

None of these are absolute solutions, but they reduce the chances of exploitation.

See also: ASUS: Critical vulnerability in DSL series routers

WordPress: Serious vulnerability in W3 Total Cache plugin

Wider implications and what this incident shows

The W3TC case is yet another example of how vulnerable the WordPress ecosystem can become because of a single plugin. With over 60,000 plugins available, the attack surface is huge — and administrators should treat updates as mandatory “daily maintenance.”

At the same time, it brings to the fore an old security truth: caching plugins, because of the way they interact with the backend, are often high-risk points in the system.

The ability to perform dynamic operations through cached content is extremely useful, but it opens doors to serious exploits if not implemented securely.

CVE-2025-9501 is one of the most serious vulnerabilities we've seen in WordPress plugins recently, largely because of the simplicity with which it can be exploited. With a simple comment, a hacker can gain full access to the server.

Upgrading to W3 Total Cache 2.8.13 is not just a "good practice" — it is absolutely necessary to protect every WordPress site that uses the plugin.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS