CVE-2021-24209
WP Super Cache prior to version 1.7.2 contained a remote code execution vulnerability accessible to authenticated administrators through the Cache Location settings option. The flaw stemmed from insufficient input validation and inadequate checks on the cache_path parameter, allowing attackers to inject a web shell via the wp-cache-config.php file which lacked proper access restrictions. The vulnerability could also be chained with cross-site scripting vulnerabilities in other plugins to achieve code execution.
Based on public CVE data (MITRE/NVD).