CVE-2025-9501Active Exploitation

MEDIUMCVSS 9.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.

5.0/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Peaked 2d ago at 2 mentions (2026-03-17); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-17: 2Mentions · 2026-04-27: 1Mentions · 2026-05-08: 1PoC Mentioned / Linked · 2026-03-17: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-04-27: 1Active Exploitation · 2026-05-08: 1Technical Details · 2026-03-17: 2Technical Details · 2026-04-27: 1Technical Details · 2026-05-08: 103-1704-2705-08
Signal classification2 categories
Active Exploitation
375.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-172
Active Exploitation1PoC1
2026-04-271
Active Exploitation1
2026-05-081
Active Exploitation1
Full discourse4 posts
  • reverseame@reverseame
    PoC

    Exploiting A Pre-Auth RCE in W3 Total Cache For WordPress <= 2.9.1 (CVE-2025-9501) #W3TotalCache #WordPress #RCE #CVE20259501 #PatchBypass https://www.rcesecurity.com/2025/11/exploiting-a-pre-auth-rce-in-w3-total-cache-for-wordpress-cve-2025-9501/

    Post summary

    The post announces a pre-authentication RCE in W3 Total Cache 2.9.1 or earlier (CVE‑2025‑9501) and links to an article containing a proof‑of‑concept exploit, but does not detail active exploitation, patching, or a false‑positive assertion.

    01031708
    21.8K followersView on X
  • Vas@vasanth_sreeram
    Active Exploitation

    But .env scraping was just phase one. It also had active exploits for: 🔹 CVE-2025-55182 — @nextjs Server Action RCE via prototype pollution (with @Cloudflare WAF bypass built in) 🔹 CVE-2025-9501 — @WordPress W3 Total Cache RCE (v2.0.x–2.8.12) @vercel

    Post summary

    The post notes that CVE‑2025‑55182 (Next.js Server Action RCE) and CVE‑2025‑9501 (WordPress W3 Total Cache RCE) are actively exploited in the wild, with mention of prototype pollution and WAF bypass, but provides no PoC, patch, or exploit tool details.

    100002
    8 followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    "PCP replaced" - the metric tracked by PCPJack's C2. PCPJack is a Linux credential-stealing worm disclosed May 7, 2026 by SentinelLabs. It exploits five CVEs to spread: - CVE-2025-29927 (Next.js middleware auth bypass) - CVE-2025-55182 "React2Shell" (Next.js Server Actions deserialization) - CVE-2026-1357 (WPVivid Backup unauth file upload) - CVE-2025-9501 (W3 Total Cache PHP injection via cached mfunc) - CVE-2025-48703 (CentOS Web Panel Filemanager shell injection) http://bootstrap.sh kills competing TeamPCP processes before installing itself, then drops six Python scripts handling orchestration, credential parsing, lateral movement, encryption, cloud-IP refresh, and port scanning. Lateral movement targets SSH, Kubernetes, Docker, Redis, RayML, MongoDB. Persistence via systemd, cron, Redis rewrites, and privileged containers. Targets pulled from Common Crawl parquet files. http://check.sh probes IMDS endpoints and Kubernetes service accounts. Credentials harvested cover Anthropic, OpenAI, HashiCorp Vault, 1Password, Slack, SSH keys, and WordPress configs. Exfil uses X25519 ECDH + ChaCha20-Poly1305, 2800-byte chunks, to Telegram. SentinelLabs links it to a likely former TeamPCP affiliate from tooling overlap. No cryptomining, unlike TeamPCP - the C2 explicitly tracks "PCP replaced" successes. A worm built to evict its predecessor and harvest the cloud underneath.

    Post summary

    SentinelLabs reports on the active exploitation of five CVEs by the PCPJack worm, which harvests credentials from cloud services, but provides no public PoC, patch, or false‑positive clarification.

    000001.3K
    153 followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: Bissa Scanner -- AI-orchestrated mass exploitation of CVE-2025-55182 (Next.js RCE) and CVE-2025-9501 (W3 Total Cache). 9 detections, 29 IOCs. https://intel.threadlinqs.com/#TL-2026-0428 #ThreatIntel #CyberSecurity #CVE #Nextjs #WordPress https://t.co/w9wVc3LQZj

    Post summary

    The intelligence indicates AI-driven mass exploitation of CVE-2025-55182 (Next.js RCE) and CVE-2025-9501 (W3 Total Cache), with multiple detections and IOCs, but no PoC, exploit code, or patch information is provided.

    00000617
    24 followersView on X

Explore more