WordPress plugin with over a million installs may have a worrying security flaw – here’s what we know


  • W3 Total Cache plugin flaw CVE-2025-9501 allows unauthorized PHP command injection
  • Affects all versions before 2.8.13; ~327,000+ websites remain at risk
  • WPScan PoC Exploitation is set for November 24, raising concerns about mass exploitation

W3 Total Cache (W3TC), a WordPress plugin with more than a million users, has a Critical Severity vulnerability that allows threat actors to fully take over compromised websites, experts have warned.

The bug is described as a command injection flaw that works by sending a comment with a malicious payload to a post. The attacker does not need to be authenticated on the site to inject PHP commands this way.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top