OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-19253

HIGH · CVSS 8.7 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Cache Enabler WordPress plugin prior to version 1.8.17 is vulnerable due to improper URL validation, enabling unauthenticated users to delete arbitrary files and directories outside the intended cache directory. This flaw poses a significant risk of data loss and site compromise for WordPress installations utilizing this plugin. Website administrators and security teams should prioritize updating to the latest version to mitigate this high-severity vulnerability.

CVE
CVE-2026-19253
Severity
HIGH
CVSS
8.7
EPSS
0.23%
WordPress

Original NVD Description

The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed Cache Enabler WordPress plugin before 1.8.17 or passes a request-derived URL to its public cache-clearing hook.