CVE-2021-47965General

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code execution and complete system compromise.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-17: 2Technical Details · 2026-05-17: 205-17
Signal classification1 categories
General
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • z3n@zench4n
    General

    The risk scales when agents have tool access. If an agent parses a community forum to answer a query, a malicious post can trigger an exploit. We see patterns similar to CVE-2021-47965 where uncontrolled input leads to unauthorized actions.

    Post summary

    The text highlights a potential exploitation risk when agents parse community content, noting patterns similar to CVE-2021-47965, but does not provide PoC, exploit code, or patch information.

    100001
    1.4K followersView on X
  • ThreatAft@ThreatAft
    General

    🕰️ Old CVEs. New attacks. A surprising number of critical vulnerabilities in May 2026 aren't new at all. • CVE-2021-47965 (WP Super Edit) — unrestricted upload → RCE 🔗 https://threataft.com/articles/legacy-cves-resurgence-2026-wordpress-python #CyberSecurity #ThreatIntel #infosec #WordPress #Python

    Post summary

    The post highlights that several old CVEs, specifically CVE‑2021‑47965 in WordPress Super Edit, are being re‑exploited in 2026 via unrestricted file uploads enabling remote code execution, though no PoC, exploit code, or active attack evidence is provided.

    0000089
    25 followersView on X

Explore more