> Exploiting A Pre-Auth RCE in W3 Total Cache For WordPress (CVE-2025-9501)
[AUTHOR: Julien Ahrens]
[DATE: 19/11/2025 17:05]
[LANGUAGE: EN]
We recently came across a very brief vulnerability announcement made by WPScan about CVE-2025-9501, which is described as an "Unauthenticated Command Injection" in the quite famous W3 Total Cache plugin for WordPress. This immediately caught our attention because with 1+ million active installations, it is one of the more wide-spread plugins, which we've also encountered numerous times in our customer pentests. Since we didn't believe that it was so easy to exploit, we decided to take WPScan's one-liner advisory, analysed the plugin's cache parsing, and build an exploit for it. Kudos to the original researcher "wcraft" who submitted this bug to WPScan.