Impact
Unauthenticated Remote Code Execution is possible in the QA Analytics plugin for WordPress through versions up to and including 5.2.0.0. The flaw allows an attacker to inject and execute arbitrary code by abusing the plugin’s input handling logic, which is a classic example of the code injection weakness described by CWE‑94. Because the injected code runs with the web server’s privileges, the impact can be full system compromise, including the ability to install backdoors, exfiltrate data, or launch further attacks against other sites on the same host.
Affected Systems
The vulnerability affects the QuarkA QA Analytics WordPress plugin, specifically versions up to and including 5.2.0.0. Any WordPress site that has this plugin installed and has not yet been updated to a supported version is potentially exposed.
Risk and Exploitability
The high severity CVSS score of 10 indicates a critical risk, and the unauthenticated nature of the flaw means that any user who can reach the affected site can exploit it. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that there is no public information about exploitation campaigns for this issue.
OpenCVE Enrichment