OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-19253 (CVSS 8.7)

NVD · officialPublished Oct 1, 2026Risk 37/100

The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed Cache Enabler WordPress plugin before 1.8.17 or passes a request-derived URL to its public cache-clearing hook.

CVSS
8.7
AV:NetworkAC:HighPR:NoneUI:NoneC:NoneI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source