CVE-2021-47965 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2021-47965 requires immediate attention.
· 7 min read
Executive Summary
CVE-2021-47965 is a critical WordPress plugin flaw affecting WP Super Edit 2.5.4 and earlier. The issue is an unrestricted file upload vulnerability in the FCKeditor component, allowing attackers to upload dangerous file types through the file manager upload endpoint without proper validation. In practical terms, this can let an attacker execute code on the server and take full control of the site and underlying system.
Severity: CRITICAL (CVSS 9.8) | KEV: No | Exploited in the wild: No
If you run a solo WordPress site or manage a small team’s deployment, treat this as an urgent containment issue: assume any exposed instance could be compromised if the vulnerable upload path is reachable.
Immediate Action
- Disable or remove WP Super Edit immediately if you do not absolutely need it. If the plugin is not business-critical, delete it from production now.
- Upgrade to a fixed release as soon as a vendor patch is available. If no patched version exists, isolate the site and disable the plugin until remediation is possible. See the vendor advisory / changelog.
- Block access to the file upload endpoint at the web server or WAF level if you must keep the site online temporarily.
- Review recent uploads and webshell indicators in the plugin directory and WordPress uploads paths. Look for unexpected
.php,.phtml,.phar, or double-extension files. - Rotate credentials for WordPress admins, hosting control panels, SSH, database users, and API keys if the site was exposed.
- Take a backup before changes, but do not restore from a potentially compromised backup without scanning it first.
Affected Versions
WP Super Edit <= 2.5.4vulnerableWP Super Edit 2.5.4 and earliervulnerableWP Super Edit >= TODO_FIXED_VERSIONsafe
If the vendor has not published a fixed version yet, treat all deployed copies as vulnerable and disable the plugin until a patched release is confirmed.
Resolution Guide
WordPress / plugin removal
# From the WordPress root
wp plugin deactivate wp-super-edit
wp plugin delete wp-super-edit
# If WP-CLI is unavailable, remove the plugin directory after backup:
rm -rf wp-content/plugins/wp-super-edit
Temporary hardening: block upload endpoint
# Nginx example: block the vulnerable filemanager upload path
location ~* /wp-content/plugins/wp-super-edit/.*/filemanager/.*upload {
deny all;
return 403;
}
# Apache example
<LocationMatch "/wp-content/plugins/wp-super-edit/.*/filemanager/.*upload">
Require all denied
</LocationMatch>
Docker / containerized WordPress
# Rebuild the image without the plugin and redeploy
docker build -t my-wordpress:patched .
docker stop wordpress
docker rm wordpress
docker run -d --name wordpress my-wordpress:patched
Linux package hygiene
WordPress plugins are usually file-based rather than apt/yum-managed, but if your deployment bakes plugins into system images, update the image and redeploy rather than patching in place.
# Debian/Ubuntu base image refresh
apt-get update && apt-get upgrade -y
# RHEL/CentOS/Fedora base image refresh
yum update -y
JavaScript/Python ecosystem note
This CVE is not an npm/pip/Maven dependency issue, but if your app bundles WordPress assets in a build pipeline, ensure the plugin is removed from source control and CI artifacts. Example cleanup:
git rm -r wp-content/plugins/wp-super-edit
git commit -m "Remove vulnerable WP Super Edit plugin"
Minimal hardening example: disable uploads in the plugin path
// Pseudocode: block upload handler at the application layer
if (request.path.includes('/filemanager/upload')) {
response.statusCode = 403;
response.end('Uploads disabled');
return;
}
Detection & Verification
Check version on disk
grep -R "Version:" wp-content/plugins/wp-super-edit/ -n
Check whether the plugin is installed and active
wp plugin list | grep -i "wp-super-edit"
Search for suspicious uploaded files
find wp-content -type f \( -name "*.php" -o -name "*.phtml" -o -name "*.phar" -o -name "*.php5" \) -mtime -30
find wp-content/uploads -type f | grep -Ei '\.(php|phtml|phar|php5)$'
Look for recent access to the upload endpoint
grep -R "filemanager/upload" /var/log/nginx /var/log/apache2 2>/dev/null
grep -R "wp-super-edit" /var/log/nginx /var/log/apache2 2>/dev/null
Verify the fix
# Confirm the plugin is gone or inactive
wp plugin list | grep -i "wp-super-edit" || echo "Plugin not installed"
# Confirm the vulnerable path now returns 403/404
curl -i https://example.com/wp-content/plugins/wp-super-edit/filemanager/upload
Dependency and file integrity checks
# Compare against a known-good backup or deployment artifact
diff -ruN /srv/backup/wp-content/plugins/wp-super-edit /var/www/html/wp-content/plugins/wp-super-edit
Risk and Impact
An attacker who can reach the upload endpoint may be able to place a webshell or other malicious file on the server, then execute commands as the web server user. From there, the blast radius can include the entire WordPress instance, database credentials, customer data, and adjacent services on the same host or container cluster. Even if there is no known active exploitation yet, the vulnerability is severe enough that exposed deployments should be treated as high-risk until the plugin is removed or patched.