Unrestricted File Upload Vulnerability in WP Super Edit by WordPress
CVE-2021-47965
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 15 May 2026
Badges
What is CVE-2021-47965?
The WP Super Edit plugin versions 2.5.4 and earlier for WordPress is susceptible to an unrestricted file upload vulnerability in the FCKeditor component. This security flaw allows unauthorized users to upload potentially malicious files to the server via the filemanager upload endpoint. The lack of input validation may lead to remote code execution, posing a serious threat to affected systems and potentially enabling attackers to gain full control over compromised installations.
Affected Version(s)
WP Super Edit 2.5.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved