Skip to content

CVE-2025-9501

CVE

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
November 18, 2025
Last Seen
December 10, 2025
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A command injection vulnerability in the W3 Total Cache plugin has exposed approximately 1 million WordPress sites to remote code execution (RCE) attacks. The vulnerability allows attackers to execute arbitrary code on affected sites, posing significant risks to website security. Site administrators...

A vulnerability identified as CVE-2025-9501 in the W3 Total Cache WordPress plugin could allow unauthenticated attackers to execute arbitrary PHP commands on affected servers. This flaw poses a significant risk to WordPress sites utilizing this plugin, potentially leading to severe security breaches...

A critical vulnerability, tracked as CVE-2025-9501, has been identified in the W3 Total Cache WordPress plugin, affecting all versions prior to 2.8.13. This flaw allows unauthenticated attackers to execute arbitrary PHP commands, potentially leading to full site takeovers for over one million instal...

A critical remote code execution vulnerability, tracked as CVE-2025-9501, has been identified in the W3 Total Cache plugin for WordPress, affecting over one million active installations. The flaw allows unauthenticated command injection, enabling attackers to execute arbitrary code on vulnerable web...

Public Exploits

Checking GitHub for proof-of-concept code…