Description
The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be installed by unauthorized users.
Published: 2026-07-07
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The DoLeads Integrator WordPress plugin and the wp2epub plugin are vulnerable in versions up to 0.65. An attacker who can upload or trigger the installation of a malicious plugin extension can cause arbitrary code to be executed on the web server. The flaw stems from insufficient access control and the ability to inject operating‑system commands when installing extensions from wordpress.org. The vulnerability allows a remote attacker to run commands on the server without authentication, providing complete compromise of the affected WordPress instance.

Affected Systems

Any WordPress site that has installed DoLeads Integrator version 0.65 or earlier, or wp2epub version 0.65 or earlier, is vulnerable. Sites that have added these plugins after an earlier installation or during a later upload window remain at risk because the exploitation path relies on the plugin installation process, which can still be triggered by unauthenticated users.

Risk and Exploitability

The flaw carries a CVSS score of 9, reflecting its high severity. The EPSS score is less than 1 % and the issue is not listed in the CISA KEV catalog, but the risk remains remote code execution. The likely attack vector is an unauthenticated request to a plugin installation or update endpoint that accepts unvalidated extensions, enabling a malicious user to inject commands that are executed on the host. The vulnerability is exploitable on any publicly accessible WordPress installation that has the affected plugin versions, until a patched version replaces them.

Generated by OpenCVE AI on July 24, 2026 at 09:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Uninstall or disable DoLeads Integrator and wp2epub from the WordPress installation immediately.
  • Upgrade both plugins to the latest released versions that fix the installation validation flaw.
  • Restrict plugin installation and update endpoints to authenticated administrators only, and consider disabling public plugin installation if it content filter for uploaded extensions to prevent malicious code or command injection.

Generated by OpenCVE AI on July 24, 2026 at 09:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-78

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-78

Wed, 15 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-78

Tue, 14 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-78

Mon, 13 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-78

Fri, 10 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-78

Fri, 10 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Thu, 09 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Wed, 08 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Tue, 07 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be installed by unauthorized users.
Title DoLeads Integrator <= 1.2.2 & wp2epub <= 0.65 - Unauthenticated RCE
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-07T13:18:43.079Z

Reserved: 2026-03-18T12:16:21.066Z

Link: CVE-2026-4375

cve-icon Vulnrichment

Updated: 2026-07-07T13:17:10.248Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T09:30:08Z

Weaknesses

No weakness.