Impact
Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress allows authenticated users with author level or higher to inject Server‑Side Template Injection via unsanitized Twig templates in the Model panel. This flaw permits arbitrary execution of PHP code and system commands, enabling attackers to compromise confidentiality, integrity, and availability of the hosting environment.
Affected Systems
WordPress sites running the Advanced Views – Display Posts, Custom Fields, and More plugin (by wplakeorg) at version 3.7.19 or older are affected. The vulnerability exists in all releases up to and including 3.7.19, regardless of other plugins or themes installed.
Risk and Exploitability
The CVSS score of 8.8 indicates severe impact, but the EPSS score of less than 1% suggests very low likelihood of exploitation in the very near term. The vulnerability is not listed in the CISA KEV catalog. An attacker would need authenticated author or higher privileges, making the attack vector an authenticated, application‑level exploitation that could lead to remote code execution on the server.
OpenCVE Enrichment
EUVD