CVE-2026-19253EPSS p12.7%

CVE-2026-19253CVE-2026-19253

Description

The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed Cache Enabler WordPress plugin before 1.8.17 or passes a request-derived URL to its public cache-clearing hook.

Scoring

CVSS 8.7 ()
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
EPSS0.23% probability of exploitation · percentile 12.7% · 2026-10-05T12:00:23Z
Last modified2026-10-01
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.