Executive brief
WP Super Edit, a WordPress plugin used to customize the website's visual editor, contains a security flaw that allows unauthorized users to upload malicious files. By exploiting this vulnerability, an attacker can gain full control over the website and its underlying server. This could lead to the theft of sensitive customer data, complete website defacement, or the installation of ransomware.
Technical details
The WP Super Edit plugin for WordPress (version 2.5.4 and earlier) is vulnerable to unrestricted file upload due to an insecure implementation of the FCKeditor component. Specifically, the filemanager upload endpoint fails to validate file extensions or types, allowing unauthenticated remote attackers to upload arbitrary files, such as PHP scripts, to the web server. By accessing the uploaded files, an attacker can achieve Remote Code Execution (RCE) with the privileges of the web server user. This vulnerability is tracked as CVE-2021-47965 and has been publicly documented with proof-of-concept exploits. No official patch has been released for this legacy plugin, which is currently considered unmaintained.
Affected products
- Ahmad Awais WP Super Edit <= 2.5.4
Timeline
- 2021-05-06: disclosed: Initial exploit published on Exploit-DB
- 2026-05-15: advisory: NVD/VulnCheck advisory published