Description
The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that covertly transmits the site URL, administrator email address, and license key to a third-party server.
Published: 2026-07-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The EscortWP WordPress theme through version 3.6.2 contains a vendor‑authored, obfuscated backdoor that allows any unauthenticated user who supplies a hard‑coded, per‑build key to permanently delete all content on a site and to silently transmit the site URL, administrator e‑mail address, and license key to a third‑party server. This flaw represents a breach of access control and results in information exposure; it is inferred that the weakness aligns with CWE‑284 (Improper Access Control) and CWE‑200 (Information Exposure).

Affected Systems

Any WordPress site that installs the EscortWP theme version 3.6.2 or older—identified in the CVE as Unknown:escortwp—is affected; no other vendors or products are listed.

Risk and Exploitability

The CVSS score of 7.5 highlights the high impact on confidentiality, integrity, and availability, while the EPSS score of < 1% indicates a very low but non‑zero probability of exploitation. The vulnerability can be triggered by an unauthenticated HTTP request containing the obsolete key, enabling the attacker to carry out the deletion and exfiltration without bypassing normal authentication. No public exploit listings appear in the CISA KEV catalog, but the guaranteed ability to erase all site content and leak sensitive data results in a high risk for sites that lack rapid recovery or backup procedures.

Generated by OpenCVE AI on July 29, 2026 at 11:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace or upgrade the EscortWP theme to a clean version newer than 3.6.2 or remove it entirely and switch to a trusted theme.
  • Scan the site’s theme and plugin directories for any remaining backdoor code and delete any malicious files found.
  • Restore the website from the most recent clean backup to recover lost content and verify that backups are intact.
  • Apply rate‑limiting or other controls to the affected endpoint to reduce the likelihood that an attacker discovers the hard‑coded key through brute‑force attempts.

Generated by OpenCVE AI on July 29, 2026 at 11:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Tue, 14 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Mon, 13 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-596
CWE-862

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-596
CWE-862

Fri, 10 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that covertly transmits the site URL, administrator email address, and license key to a third-party server.
Title EscortWP <= 3.6.2 - Content Deletion via Vendor-Authored Backdoor
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-10T15:04:42.106Z

Reserved: 2026-06-19T08:15:52.985Z

Link: CVE-2026-12685

cve-icon Vulnrichment

Updated: 2026-07-10T15:04:32.284Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control