Impact
The Advanced Views plugin contains an arbitrary code execution flaw (CWE‑94) that can be triggered by an attacker through the subscriber feature. If exploited, the attacker can run any PHP code on the WordPress site, compromising confidentiality, integrity, and availability of the server and the data it hosts.
Affected Systems
WordPress sites running the WPLake Advanced Views plugin version 3.8.11 or older and which have enabled the subscriber functionality are vulnerable. No other WordPress versions or plugins are listed as affected.
Risk and Exploitability
The vulnerability has a CVSS score of 9.9, rating it as critical, and a very low EPSS score (< 1%) which indicates that exploitation in the wild is currently scarce. It is not listed in CISA’s KEV catalog. The attack vector is inferred to involve a remote actor accessing the subscriber endpoint of the vulnerable plugin to trigger the flaw, as the description references a Subscriber Remote Code Execution scenario.
OpenCVE Enrichment