Impact
The Cache Enabler WordPress plugin before version 1.8.17 fails to validate a URL used in its cache‑purge routine, building a filesystem path directly from that value and then deleting the target. Because the deletion is not confined to the plugin’s cache directory, an unauthenticated attacker can direct the routine to delete any file or directory that the web server can write to. This flaw—an instance of path traversal (CWE‑73)—allows complete data loss and can compromise the integrity of the site by removing critical files, including application code, configuration files, or user uploads.
Affected Systems
WordPress installations that have the Cache Enabler plugin installed in any version earlier than 1.8.17 are affected. The vulnerability arises when a request‑derived URL is passed to the public cache‑clearing hook of the plugin.
Risk and Exploitability
The flaw is exploitable by any user who can craft a request that triggers the cache‑clearing hook, which is unauthenticated and publicly accessible on the WordPress site. The EPSS score is unavailable and the vulnerability is not listed in CISA KEV. With a CVSS score of 8.7, the risk is high; an attacker could remove essential system, potentially taking the site offline or facilitating further compromise. The lack of authentication and the ability to delete arbitrary files make the impact severe.
OpenCVE Enrichment