MajorCritical vulnerability
CVE-2026-19253 (CVSS 8.7)
NVD · officialPublished Oct 1, 2026Risk 37/100
The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed Cache Enabler WordPress plugin before 1.8.17 or passes a request-derived URL to its public cache-clearing hook.
Technical details
CVSS
8.7
AV:NetworkAC:HighPR:NoneUI:NoneC:NoneI:HighA:High
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source