Description
Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
Published: 2026-08-06
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated Remote Code Execution vulnerability exists in the Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin version 2.1.3 and earlier. The flaw allows an attacker to inject and execute arbitrary code through the plugin’s input handling, potentially compromising the entire WordPress installation. The associated weakness is classified as CWE‑94, indicating an improper handling of evaluated code. The impact includes full control over the affected server, data theft, defacement, and further lateral movement. The vulnerability is severe because it does not require authentication to exploit.

Affected Systems

WordPress sites that have the Spider Analyser plugin installed with a version equal to or older than 2.1.3. The plugin is distributed by wbolt.com and is used to analyze search engine spiders. Any WordPress installation running the impacted plugin becomes a valid target.

Risk and Exploitability

The CVSS score of 10 reflects a critical severity. Although the EPSS score is not available, the lack of exploitation data does not diminish the risk; the high CVSS score indicates that an attacker could easily gain remote code execution. The vulnerability is not listed in the CISA KEV catalog, but the unauthenticated execution vector means that an attacker could compromise a site without user interaction. If the plugin is accessible via the public web interface, the attack can be launched from any remote location.

Generated by OpenCVE AI on August 6, 2026 at 15:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Spider Analyser plugin to the latest release that removes the code‑execution flaw.
  • If the plugin is not required, uninstall or disable it entirely to eliminate the attack surface.
  • Conduct a manual file integrity check of the plugin directory and audit any recently added files for malicious content.

Generated by OpenCVE AI on August 6, 2026 at 15:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
Title WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:36.157Z

Reserved: 2026-07-22T08:54:23.961Z

Link: CVE-2026-65553

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:00:06Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')