Unrated severityNVD Advisory· Published Oct 1, 2026
CVE-2026-19253
CVE-2026-19253
Description
The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed Cache Enabler WordPress plugin before 1.8.17 or passes a request-derived URL to its public cache-clearing hook.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.8.17
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.