Impact
The Defender Security WordPress plugin prior to version 6.2.0 contains an improper privilege escalation weakness that allows a single‑site administrator on a multisite network to modify a setting that should be restricted to network administrators. By doing so, the attacker can inject and execute arbitrary PHP code across all sites within the network (CWE‑94). This results in full remote code execution affecting every site on the multisite installation, compromising confidentiality, integrity, and availability of all sites.
Affected Systems
This flaw affects installations of the Defender Security WordPress plugin version 6.1.x and earlier running on WordPress multisite deployments. The plugin is widely used for centralized security management and is typically installed on networks with multiple sub‑sites.
Risk and Exploitability
With a CVSS score of 6.6 and an EPSS probability of less than 1 %, the vulnerability is considered high‑severity but not yet widely exploited. Because the attacker only needs the ability to log in as a single‑site administrator—an access level that attackers often target—the threat remains practical. The absence of a KEV listing indicates no publicly documented exploitation yet, but the potential impact justifies prioritizing mitigation.
OpenCVE Enrichment