Description
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
Published: 2026-07-23
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Advanced Views plugin contains an arbitrary code execution flaw (CWE‑94) that can be triggered by an attacker through the subscriber feature. If exploited, the attacker can run any PHP code on the WordPress site, compromising confidentiality, integrity, and availability of the server and the data it hosts.

Affected Systems

WordPress sites running the WPLake Advanced Views plugin version 3.8.11 or older and which have enabled the subscriber functionality are vulnerable. No other WordPress versions or plugins are listed as affected.

Risk and Exploitability

The vulnerability has a CVSS score of 9.9, rating it as critical, and a very low EPSS score (< 1%) which indicates that exploitation in the wild is currently scarce. It is not listed in CISA’s KEV catalog. The attack vector is inferred to involve a remote actor accessing the subscriber endpoint of the vulnerable plugin to trigger the flaw, as the description references a Subscriber Remote Code Execution scenario.

Generated by OpenCVE AI on August 3, 2026 at 22:18 UTC.

Remediation

Vendor Solution

Update the WordPress Advanced Views Plugin to the latest available version (at least 3.9.0).


OpenCVE Recommended Actions

  • Update the Advanced Views plugin to at least version 3.9.0.
  • If an update cannot be applied immediately, uninstall or disable the plugin to remove the vulnerable code path.
  • Configure a firewall or WAF rule to block any access to the subscriber endpoint until the plugin is updated.

Generated by OpenCVE AI on August 3, 2026 at 22:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wplake
Wplake advanced Views
Vendors & Products Wordpress
Wordpress wordpress
Wplake
Wplake advanced Views

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
Title WordPress Advanced Views plugin <= 3.8.11 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
Wplake Advanced Views
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:52:46.087Z

Reserved: 2026-07-05T21:27:56.024Z

Link: CVE-2026-59543

cve-icon Vulnrichment

Updated: 2026-07-23T14:07:55.686Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:33.193

Modified: 2026-07-23T15:17:26.207

Link: CVE-2026-59543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:30:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')