WordPress plugin with over a million installs may have a worrying security flaw – here’s what we know



  • W3 Total Cache plugin flaw CVE-2025-9501 enables unauthenticated PHP command injection
  • Affects all versions before 2.8.13; ~327,000+ sites remain at risk
  • WPScan PoC exploit set for Nov 24, raising mass exploitation concerns

W3 Total Cache (W3TC), a WordPress plugin with more than a million users, carries a critical-severity vulnerability that allows threat actors to fully take over compromised websites, experts have warned.

The bug is described as a command injection flaw that works by submitting a comment with a malicious payload to a post. The attacker does not need to be authenticated on the website in order to inject PHP commands this way.


https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img