{
    "id": "CVE-2025-9501",
    "published": "2025-11-17 06:15:45",
    "last_modified": "2026-06-17 10:09:07",
    "cvss_score": "9.0",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "cwe": null,
    "description": "The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.",
    "epss_score": "0.22631",
    "epss_percentile": "0.97661",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-03 18:17:55",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "EPSS 22.6% — above the 10% action threshold."
    },
    "products": [],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://wpscan.com/vulnerability/6697a2c9-63ae-42f0-8931-f2e5d67d45ae/"
    ]
}