Impact
An unauthenticated Remote Code Execution vulnerability exists in the Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin version 2.1.3 and earlier. The flaw allows an attacker to inject and execute arbitrary code through the plugin’s input handling, potentially compromising the entire WordPress installation. The associated weakness is classified as CWE‑94, indicating an improper handling of evaluated code. The impact includes full control over the affected server, data theft, defacement, and further lateral movement. The vulnerability is severe because it does not require authentication to exploit.
Affected Systems
WordPress sites that have the Spider Analyser plugin installed with a version equal to or older than 2.1.3. The plugin is distributed by wbolt.com and is used to analyze search engine spiders. Any WordPress installation running the impacted plugin becomes a valid target.
Risk and Exploitability
The CVSS score of 10 reflects a critical severity. Although the EPSS score is not available, the lack of exploitation data does not diminish the risk; the high CVSS score indicates that an attacker could easily gain remote code execution. The vulnerability is not listed in the CISA KEV catalog, but the unauthenticated execution vector means that an attacker could compromise a site without user interaction. If the plugin is accessible via the public web interface, the attack can be launched from any remote location.
OpenCVE Enrichment