CyberRota Analysis
AI-GeneratedThe Cache Enabler WordPress plugin prior to version 1.8.17 is vulnerable due to improper URL validation, enabling unauthenticated users to delete arbitrary files and directories outside the intended cache directory. This flaw poses a significant risk of data loss and site compromise for WordPress installations utilizing this plugin. Website administrators and security teams should prioritize updating to the latest version to mitigate this high-severity vulnerability.
Original NVD Description
The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed Cache Enabler WordPress plugin before 1.8.17 or passes a request-derived URL to its public cache-clearing hook.