CVE-2026-59543

WPLake · Advanced Views

The WPLake Advanced Views WordPress plugin contains a code injection vulnerability allowing remote code execution for authenticated subscribers.

Executive summary

A critical remote code execution vulnerability in the WPLake Advanced Views plugin allows authenticated subscribers to execute arbitrary code on the underlying server.

Vulnerability

The plugin is susceptible to CWE-94, which is improper control of generation of code, specifically code injection. The vulnerability is exploitable by an attacker with subscriber-level privileges, meaning a low-privileged authenticated user can achieve full system compromise.

Business impact

Successful exploitation grants an attacker full control over the WordPress environment and the hosting server. Given the CVSS score of 9.9, this vulnerability poses an extreme risk of complete data loss, unauthorized administrative access, and potential lateral movement within the hosting infrastructure.

Remediation

Immediate Action: Update the WPLake Advanced Views plugin to version 3.9.0 or the latest available version immediately.

Proactive Monitoring: Review web server access logs for unusual requests originating from authenticated subscriber accounts that target plugin-specific endpoints.

Compensating Controls: Deploy a Web Application Firewall (WAF) to block malicious payloads targeting WordPress plugin code injection vectors.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a severe threat to the integrity and confidentiality of the WordPress installation. Administrators must prioritize updating the Advanced Views plugin to version 3.9.0 without delay to neutralize the risk of remote code execution.