The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed Cache Enabler WordPress plugin before 1.8.17 or passes a request-derived URL to its public cache-clearing hook.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-19253 is a critical path traversal vulnerability in the Cache Enabler WordPress plugin that allows unauthenticated attackers to delete arbitrary files and directories on vulnerable servers. The plugin fails to validate user-supplied URLs before using them to construct filesystem paths in its cache purge routine, and critically, does not restrict deletion operations to the cache directory. This means an attacker can craft malicious requests that traverse outside intended boundaries using path manipulation techniques (e.g., "../../../") to target sensitive system files, configuration files, or other critical data. Any WordPress site running Cache Enabler before version 1.8.17 is affected, with exploitation requiring no authentication—making this a high-severity risk for the estimated millions of WordPress installations using this plugin.
While this CVE does not map directly to existing MITRE ATT&CK techniques in Casky's current skill set, the underlying attack pattern represents a classic Input Validation failure (CWE-73) that would be detected through Casky's extended reasoning capabilities by identifying suspicious file deletion patterns and path traversal indicators in server logs and request patterns. A practitioner using Casky would observe findings related to unusual DELETE or unlink operations targeting files outside the wp-content/cache directory, unexpected file system access to sensitive paths like wp-config.php or /etc/, and unauthenticated HTTP requests containing encoded or obfuscated path traversal sequences (../, ..\, or URL-encoded variants). The AI-driven analysis would correlate these indicators as potential exploitation attempts even in the absence of direct ATT&CK mapping, flagging the attack pattern's destructive intent and the need for immediate plugin updates and WAF rules to block requests with path traversal payloads.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-19253. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation