PT-2025-30387 · WordPress · Nginx Cache Purge Preload

Cynau1T

·

Published

2025-07-22

·

Updated

2025-07-22

·

CVE-2025-6213

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nginx Cache Purge Preload plugin for WordPress versions through 2.1.1
Description The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution via the nppp preload cache on update function. This is due to insufficient sanitization of the $ SERVER['HTTP REFERERER'] parameter passed from the nppp handle fastcgi cache actions admin bar function. This allows authenticated attackers with Administrator-level access and above to execute code on the server.
Recommendations Nginx Cache Purge Preload plugin for WordPress versions through 2.1.1: Update to a version later than 2.1.1.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-6213

Affected Products

Nginx Cache Purge Preload