CVE-2026-73992

9.9

Jonathan Daggerhart · Query Wrangler

A remote code execution vulnerability exists in the Query Wrangler WordPress plugin, allowing authenticated subscribers to execute arbitrary code.

Executive summary

The Query Wrangler plugin for WordPress is vulnerable to remote code execution by authenticated users, posing a critical risk of full system compromise.

Vulnerability

This vulnerability involves improper control of code generation, categorized as CWE-94. It allows an authenticated user with subscriber-level privileges to inject and execute arbitrary code on the host server.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code, potentially leading to complete system takeover, unauthorized access to sensitive database information, and significant operational disruption. Given the CVSS score of 9.9, this flaw represents a critical risk to the confidentiality, integrity, and availability of the affected WordPress environment.

Remediation

Immediate Action: Update the Query Wrangler plugin to version 1.5.58 or later immediately to resolve the code injection flaw.

Proactive Monitoring: Review web server access logs for suspicious requests involving unusual parameters or attempts to execute system-level commands.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common code injection patterns and restrict access to administrative or sensitive plugin endpoints.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a severe risk that requires immediate attention. Administrators must prioritize updating the Query Wrangler plugin to the patched version to prevent potential remote code execution and maintain the security integrity of the WordPress instance.

More Jonathan Daggerhart CVEs