W3 Total Cache WordPress Plugin Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the W3 Total Cache WordPress plugin, affecting versions prior to 2.8.13. The vulnerability arises in the _parse_dynamic_mfunc function, where unauthenticated users can execute PHP commands by submitting a comment with a malicious payload to a post.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the server where WordPress is hosted.

Remediation

Users are advised to update the W3 Total Cache WordPress plugin to version 2.8.13 or later.

Added: Nov 17, 2025, 6:17 AM
Updated: Nov 17, 2025, 6:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.7
remediation
7.7
relevance
1.0
threat
6.5
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.