CVE-2021-47965 PUBLISHED

WordPress Plugin WP Super Edit 2.5.4 Unrestricted File Upload

Assigner: VulnCheck
Reserved: 15.05.2026 Published: 15.05.2026 Updated: 15.05.2026

WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code execution and complete system compromise.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor wp-super-edit
Product WP Super Edit
Versions
  • Version 2.5.4 is affected

Credits

  • h4shur finder

References

Problem Types

  • Unrestricted Upload of File with Dangerous Type CWE