vulnerability

WordPress Plugin: wp-super-cache: CVE-2021-24209: Improper Input Validation

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Mar 16, 2021
Added
May 15, 2025
Modified
Jun 24, 2025

Description

The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -greater than Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.

Solution

wp-super-cache-plugin-cve-2021-24209
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.