PT-2026-56150 · WordPress · Wp2Epub+1
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DoLeads Integrator versions prior to 1.2.3
wp2epub versions prior to 0.66
Description
Remote Code Execution (RCE) can be achieved when these plugins are added to a blog. This can occur through a process where unauthorized users install unclosed extensions from wordpress.org.
Recommendations
Update DoLeads Integrator to version 1.2.3 or later.
Update wp2epub to version 0.66 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Doleads Integrator
Wp2Epub