Record summary

CVE-2021-47965 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code execution and complete system compromise.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 15, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListThrough 2.5.4affected

Proofs of concept

1

Catalogued exploits

ExploitDBWordpress Plugin WP Super Edit 2.5.4 - Remote File UploadExploitDB exploitby h4shurNot analyzed1 file
ExploitDB

PoC details

References

5