Impact
The vulnerability is an Improper Control of Generation of Code flaw that allows attackers to inject and execute arbitrary code within the WordPress RD Station plugin. By exploiting this code injection weakness, attackers could gain complete control over the infected WordPress site, compromising the confidentiality, integrity, and availability of the site and potentially the underlying server infrastructure. This weakness corresponds to CWE-94.
Affected Systems
The RD Station WordPress plugin, released by Filipe Nasc:RD Station, is affected in all versions up to and including 5.6.0. Any WordPress site that has this plugin installed at a vulnerable version is at risk.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely to be widespread. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through crafted HTTP requests targeting a remote code inclusion endpoint within the plugin; the exact prerequisites are not detailed in the available data.
OpenCVE Enrichment