W3 Total Cache is vulnerable to Command Injection
90
Critical Risk
Affected versions of the W3 Total Cache plugin are vulnerable to command injection in the _parse_dynamic_mfunc function, allowing unauthenticated users to execute arbitrary PHP code by submitting a comment containing a crafted malicious payload on a post.
You are affected if you are using a version that falls within the vulnerable range.
W3 Total Cache is vulnerable to Command Injection in versions 0.0.1 - 2.8.12.
Upgrade the W3 Total Cache library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant