CVE-2021-47965

CRITICAL

WordPress Plugin WP Super Edit 2.5.4 Unrestricted File Upload

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47965. PoCs published by h4shur.

AI-analyzed exploit summary The exploit demonstrates an unrestricted file upload vulnerability in the WordPress WP Super Edit plugin (version 2.5.4 and earlier) via FCKeditor's file manager. Attackers can upload malicious files to achieve remote code execution (RCE) by accessing specific endpoints.

Description

WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code execution and complete system compromise.

Exploits (1)

exploitdb WORKING POC
by h4shur · textwebappsphp
https://www.exploit-db.com/exploits/49839

The exploit demonstrates an unrestricted file upload vulnerability in the WordPress WP Super Edit plugin (version 2.5.4 and earlier) via FCKeditor's file manager. Attackers can upload malicious files to achieve remote code execution (RCE) by accessing specific endpoints.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress WP Super Edit plugin <= 2.5.4
No auth needed
Prerequisites: Access to the vulnerable plugin's file manager endpoints
devstral-2 · analyzed May 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-49839
https://www.exploit-db.com/exploits/49839
Product product
Official Product Homepage
https://wordpress.org
Product product
Product Reference
https://wordpress.org/plugins/wp-super-edit/
Third Party Advisory third-party-advisory
VulnCheck Advisory: WordPress Plugin WP Super Edit 2.5.4 Unrestricted File Upload
https://www.vulncheck.com/advisories/wordpress-plugin-wp-super-edit-unrestricted-file-upload

Scores

CVSS v3 9.8
EPSS 0.0058
EPSS Percentile 42.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
wp-super-edit/WP Super Edit < 2.5.4
wp-super-edit/WP Super Edit 2.5.4
Published May 15, 2026
Tracked Since May 16, 2026