WordPress Plugin Vulnerabilities

W3 Total Cache < 2.8.13 - Unauthenticated Command Injection

Description

The plugin is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.

Proof of Concept

Affects Plugins

Image Fixed in 2.8.13

References

Classification

Type
COMMAND INJECTION
OWASP top 10
CWE

Miscellaneous

Original Researcher
wcraft
Submitter
wcraft
Verified
Yes

Timeline

Publicly Published
2025-10-27 (about 1 month ago)
Added
2025-10-27 (about 1 month ago)
Last Updated
2025-10-27 (about 1 month ago)

Other