nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47965 CVE-2021-47965
CRITICAL
WordPress Plugin WP Super Edit 2.5.4 Unrestricted File Upload
Record summary
CVE-2021-47965 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code execution and complete system compromise.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 15, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WP Super EditBrowse wp-super-edit / WP Super Edit | CVE List | Through 2.5.4 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordpress Plugin WP Super Edit 2.5.4 - Remote File UploadExploitDB exploitby h4shurNot analyzed1 file
References
5Official Product Homepageproduct
https://wordpress.org/ Product Referenceproduct
https://wordpress.org/plugins/wp-super-edit ExploitDB-49839exploit
https://www.exploit-db.com/exploits/49839 VulnCheck Advisory: WordPress Plugin WP Super Edit 2.5.4 Unrestricted File UploadThird-party advisory
https://www.vulncheck.com/advisories/wordpress-plugin-wp-super-edit-unrestricted-file-upload