Impact
The DoLeads Integrator WordPress plugin and the wp2epub plugin are vulnerable in versions up to 0.65. An attacker who can upload or trigger the installation of a malicious plugin extension can cause arbitrary code to be executed on the web server. The flaw stems from insufficient access control and the ability to inject operating‑system commands when installing extensions from wordpress.org. The vulnerability allows a remote attacker to run commands on the server without authentication, providing complete compromise of the affected WordPress instance.
Affected Systems
Any WordPress site that has installed DoLeads Integrator version 0.65 or earlier, or wp2epub version 0.65 or earlier, is vulnerable. Sites that have added these plugins after an earlier installation or during a later upload window remain at risk because the exploitation path relies on the plugin installation process, which can still be triggered by unauthenticated users.
Risk and Exploitability
The flaw carries a CVSS score of 9, reflecting its high severity. The EPSS score is less than 1 % and the issue is not listed in the CISA KEV catalog, but the risk remains remote code execution. The likely attack vector is an unauthenticated request to a plugin installation or update endpoint that accepts unvalidated extensions, enabling a malicious user to inject commands that are executed on the host. The vulnerability is exploitable on any publicly accessible WordPress installation that has the affected plugin versions, until a patched version replaces them.
OpenCVE Enrichment