Cache Enabler
Cache Enabler (cache-enabler) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Oct 01, 2026; an upstream CVSS base score is still pending.
cache-enablerCVE-2026-19253: Cache Enabler: Arbitrary file deletion
The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed component passes a request-derived URL to its public cache-clearing hook. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 1.8.17.
| Safe version |
|
||
|---|---|---|---|
| Oct 01, 2026 |
CVE-2026-19253
Cache Enabler: Arbitrary file deletion
The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed component passes a request-derived URL to its public cache-clearing hook. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 1.8.17.
|
1.8.17 |
CVEPending
NVDPending
|