VYPR

Wp Super Edit

Sign in to watch

by WordPress

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2021-47965Cri0.649.80.00May 15, 2026WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code execution and complete system compromise.
CVE-2025-49948Hig0.467.10.00Oct 22, 2025Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad Awais WP Super Edit wp-super-edit allows Reflected XSS.This issue affects WP Super Edit: from n/a through <= 2.5.4.