← WordPress Vulnerabilities
WordPress security by component

Cache Enabler

Cache Enabler (cache-enabler) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Oct 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: cache-enabler

CVE-2026-19253: Cache Enabler: Arbitrary file deletion

The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed component passes a request-derived URL to its public cache-clearing hook. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 1.8.17.

PublishedOct 01, 2026
Known safe version1.8.17
Published vulnerabilities for cache-enabler
Safe version
Oct 01, 2026 CVE-2026-19253
Cache Enabler: Arbitrary file deletion
The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed component passes a request-derived URL to its public cache-clearing hook. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 1.8.17.
1.8.17
CVEPending
NVDPending