PT-2026-39960 · Thewebsitesupply+1 · Gwd Conex+1

·

CVE-2026-6663

·

Published

2026-05-11

·

Updated

2026-05-12

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GWD Connect plugin for WordPress versions prior to 2.10
Description Missing authorization in the plugin allows limited code execution on unregistered installations in certain environments. The issue occurs because the standalone agent endpoints 'gwd-backup.php' and 'gwd-logs.php' do not verify authentication when the API key is not configured, which is the default state. Unauthenticated attackers can execute arbitrary code on the server via the update agent action, which writes attacker-supplied PHP code to the agent file.
Recommendations Update the GWD Connect plugin for WordPress to version 2.10 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6663

Affected Products

Gwd Conex
Graphic-Web-Design-Inc