CVE-2026-14498

8.8

Daggerhart · Query Wrangler

The Query Wrangler plugin for WordPress is susceptible to Remote Code Execution via an unrestricted file upload vulnerability, which can be exploited by authenticated users.

Executive summary

The Query Wrangler plugin for WordPress contains a critical Remote Code Execution vulnerability that could allow an authenticated attacker to compromise the host server.

Vulnerability

The plugin is vulnerable to CWE-434, where improper validation allows an authenticated user to upload malicious files, leading to Remote Code Execution.

Business impact

An attacker successfully exploiting this vulnerability could execute arbitrary code, leading to total system compromise, data theft, or the installation of persistent backdoors. The CVSS score of 8.8 reflects the high potential for impact and the relative ease of exploitation for an authenticated user.

Remediation

Immediate Action: Update the Query Wrangler plugin to version 1.5.58 or later immediately.

Proactive Monitoring: Audit server file systems for unexpected files or scripts in plugin-related directories.

Compensating Controls: Utilize a WAF to restrict access to administrative functions and detect malicious file upload attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Immediate remediation is required to secure the environment against potential Remote Code Execution attacks. Administrators should verify that all installations are updated to version 1.5.58 and review access logs for any suspicious activity involving the plugin.