CVE-2021-24209

HIGH EXPLOITED

WP Super Cache < 1.7.2 - Authenticated Remote Code Execution via Cache Location Setting

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-24209 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/733d8a02-0d44-4b78-bbb2-37e447acd2f3

Scores

CVSS v3 7.2
EPSS 0.2384
EPSS Percentile 97.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2021-12-09
CWE
CWE-94
Status published
Products (1)
automattic/wp_super_cache < 1.7.2
Published Apr 05, 2021
Tracked Since Feb 18, 2026