CVE-2026-32414

7.2

ILLID · Advanced Woo Labels

A code injection vulnerability in the Advanced Woo Labels plugin allows for remote code inclusion by an authenticated administrator.

Executive summary

A remote code injection vulnerability in the ILLID Advanced Woo Labels plugin poses a significant threat by allowing attackers with administrative privileges to execute arbitrary code.

Vulnerability

The plugin contains a flaw categorized as CWE-94, which allows for improper control of code generation. An attacker with high-level administrative privileges can leverage this to achieve remote code inclusion, potentially leading to full system compromise.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the underlying server, leading to a complete compromise of the WordPress environment. Given the high CVSS score of 7.2, the risk of data exfiltration, site defacement, or lateral movement within the network is significant, necessitating an urgent response to secure administrative access.

Remediation

Immediate Action: Since a specific patch version is not currently identified, administrators should immediately disable or uninstall the Advanced Woo Labels plugin until a secure update is released by the vendor.

Proactive Monitoring: Review web server and WordPress application logs for suspicious activity or unauthorized file modifications originating from administrative user accounts.

Compensating Controls: Implement strict file integrity monitoring and ensure that administrative access to the WordPress dashboard is restricted to trusted IP addresses via a Web Application Firewall (WAF) or VPN.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The vulnerability represents a critical risk to the integrity and availability of the affected WordPress site. Because the plugin allows for remote code execution, it is imperative that organizations prioritize the removal or containment of this component until the vendor provides a verified security update. Failure to address this could result in a complete system takeover by unauthorized parties.

Sources

Originally found and disclosed by Trương Hữu Phúc (truonghuuphuc) | Patchstack Bug Bounty Program, per the CVE Program record.