WordPress security changelog
UNKNOWN CVE-2026-19253 Received

Cache Enabler: Arbitrary file deletion

The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed component passes a request-derived URL to its public cache-clearing hook. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 1.8.17.

CVE / CNA score Pending The CVE record has not published a CNA CVSS assessment.
NVD score Pending NVD has not published its own CVSS assessment.
Component
Cache Enabler
Plugin slug
cache-enabler
Affected
< 1.8.17
Safe version
1.8.17
Published
Oct 01, 2026
Weakness
Not assigned

This CVE was published Oct 01, 2026 and is one of 1 known issue for this plugin.

Update, patch or deactivate.

Update Cache Enabler to 1.8.17 or a later supported release. Validate and canonicalize URL-derived paths and confine every deletion to the intended cache directory, including paths supplied by other components through the public hook.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed Cache Enabler WordPress plugin before 1.8.17 or passes a request-derived URL to its public cache-clearing hook.

Primary and upstream sources